Remote work is no longer limited to large corporations. Even a single skilled nursing facility may have a billing specialist, an MDS coordinator, a regional manager or an on-call clinician who needs to reach systems from home or the road. Remote access is also one of the most frequently abused entry points in healthcare cyberattacks, particularly when it was set up quickly and never revisited. Done well, it is safe and convenient. Done poorly, it is an open door.
Exposed services. Remote desktop or other management ports reachable from the internet are scanned constantly by attackers.
Weak or reused passwords without a second factor.
Unmanaged home computers that may carry malware or lack updates.
Home networks with default router passwords, shared by family members and smart devices.
Data leaving the building. Files downloaded to personal devices or printed at home escape your controls.
Forgotten accounts. Former employees and vendors with working remote credentials.
There are several common models. The best fit depends on your systems and staff.
If your EMR and key applications are web-based, staff may need only a browser and secure login. Enforce multi-factor authentication, restrict by role, and consider conditional rules, such as blocking sign-in from countries where you have no staff.
A VPN creates an encrypted tunnel from the user's device to your network. It works well when staff need access to internal file shares or applications. Keep the VPN gateway patched, require MFA, and limit what VPN users can reach rather than giving full network access.
Staff connect to a desktop that stays inside your environment, and data remains there. This approach is attractive for PHI, because nothing is stored on the home computer. Never expose remote desktop directly to the internet. Place it behind a secure gateway or VPN with MFA.
Some staff connect to their office computer. This is convenient but makes the office computer a target, and it needs the same protections.
Whatever model you choose, set these baseline requirements:
Multi-factor authentication for every remote login.
Unique accounts, no sharing, and prompt removal on departure.
Least privilege. Give remote users only the access their role needs.
Encryption of connections and of any device that stores data.
Device standards. Prefer organization-owned laptops with managed security, disk encryption, automatic updates and endpoint protection. If personal devices are allowed, require minimum standards and use a managed profile or virtual desktop to keep PHI contained.
Session limits. Automatic timeouts and screen locks.
Logging and monitoring. Record logins, watch for unusual locations or times, and alert on repeated failures.
Up-to-date software. Patch VPN appliances, gateways and remote tools promptly.
Provide a short guide for remote employees covering:
Changing the default password on the home router and keeping its firmware updated.
Using a separate area or screen position that others cannot view.
Never letting family members use work devices.
Not printing PHI at home, and shredding anything that must be printed.
Locking the screen when stepping away.
Avoiding public Wi-Fi without a VPN, and being careful with PHI in public places.
Reporting lost or stolen devices immediately.
Outside vendors who support your software or equipment often use remote tools. Treat them as high-risk connections:
Require individual named accounts, not a shared vendor login.
Enable access only when needed, with time limits.
Log and review sessions where possible.
Make sure a business associate agreement is in place.
Remove access when the project ends.
Write a remote access policy that covers who is eligible, approved methods, device requirements, acceptable use, and consequences for violations. The HIPAA Security Rule requires access controls, transmission security and workstation security policies, and remote work falls within them. Include remote access in your risk analysis.
Every quarter, review the list of people with remote access, remove unused accounts, and verify that your VPN or gateway is current. Test the setup with a short internal assessment to confirm that no unexpected services are reachable from the internet.
UnityCare IT designs and manages secure remote access for healthcare organizations, including VPN, MFA and managed devices. If you suspect that remote access was set up years ago and not revisited, we can review it and recommend changes that keep staff productive and the network protected.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034