Vendor Remote Access: Closing a Common Back Door

Think about everyone who can connect to your network from outside the building. Your EHR vendor, a copier company, the phone system installer, the camera integrator, a billing partner, your IT provider, a medical device manufacturer. Each one may have a remote access tool, a VPN account or a shared password. Attackers know this, and compromising a vendor can be easier than compromising you directly.

Vendor remote access is useful and often necessary. The aim is to make sure it is controlled, visible and temporary wherever possible.

Why this risk is easy to overlook

Remote access is usually set up during installation or an urgent problem, and then forgotten. Over time:

Accounts remain active after projects end

Passwords are shared among several vendor technicians

Remote tools stay installed on servers and workstations

Nobody inside the organization knows which vendor has access to what

Logs are not reviewed

The HIPAA Security Rule expects you to manage access to systems holding ePHI, and a vendor with a persistent, unmonitored connection is part of that picture.

Step 1: Find all remote access paths

Create an inventory. Sources include:

Firewall rules and VPN user lists

Remote desktop and remote support software installed on computers and servers

Port forwarding rules that expose internal devices to the internet

Cellular modems or remote management boxes installed by vendors

Cloud portals that connect into your environment

Vendor lists from accounts payable and contracts

For each path, record the vendor, purpose, systems reached, who approved it and when it was last used.

Step 2: Remove what is not needed

If a vendor has not used a path in months, disable it. If a project has ended, close the access. Vendors can always be reconnected when needed, so the cost of turning it off is small.

Step 3: Require secure methods

Set standards for how vendors connect:

Individual named accounts, not shared logins, so that each action can be traced

Multi-factor authentication for every vendor account

Connection through a controlled gateway or VPN, not by exposing a system directly to the internet

Access limited to the specific systems and functions required

Encryption of all remote sessions

Exposing remote desktop directly to the internet has been a frequent factor in ransomware incidents, so check that none of your systems are reachable that way.

Step 4: Make access time-bound

Where possible, keep vendor accounts disabled by default and enable them when work is scheduled. Some organizations require a phone call or ticket before each session, and watch the session while it occurs. For critical systems, consider session recording.

Step 5: Put it in the contract

Your agreements and business associate agreements should cover security expectations:

Vendor staff must use the approved method and not share credentials

Vendors must protect their own systems and notify you of incidents that could affect you

Technicians must complete appropriate training

Access ends when the contract ends, and you can verify it

The vendor will not move data off your systems without permission

Step 6: Monitor and review

Turn on logging for remote sessions and VPN activity

Alert on logins outside expected hours or from unusual locations

Review the access list every quarter, and ask each business owner whether each vendor still needs access

Include vendor access in your annual HIPAA risk analysis

Special case: medical and building devices

Some devices come with vendor-managed remote support that you cannot easily configure. Treat these carefully.

Ask the manufacturer how remote support works and whether it can be disabled except during service

Place the device on an isolated network segment

Limit its outbound connections to what the vendor documents

What to do if a vendor reports a breach

Have a plan for incoming notices. Identify what data or access the vendor had, rotate any credentials or keys shared with them, review logs for suspicious activity, and have your privacy officer assess whether HIPAA breach notification obligations apply to you.

A quick checklist

Do we know every vendor with remote access?

Does each technician have a unique account?

Is MFA required?

Is access limited to what is needed?

Are old accounts and tools removed?

Are sessions logged and reviewed?

If you answered no to several of these, you are not alone. UnityCare IT helps healthcare and senior-living organizations inventory vendor access, tighten it and monitor it, and we can walk through your current list with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172