Care facilities rely on many outside companies that need to reach your systems: the EMR support team, a pharmacy interface vendor, the copier technician, the nurse call company, the camera installer, the phone provider. Each may ask for remote access, and each request is easy to grant in the moment. Over time, a facility can end up with permanent remote tools installed on servers, shared vendor passwords written in a notebook and no clear picture of who can get in.
Third-party access has played a role in many publicly reported breaches across industries, because attackers target the weakest link in the supply chain. Managing it well is a practical step with real payoff.
Vendors often use shared accounts, so actions cannot be traced to a person
Remote tools may stay installed and accessible long after the project ends
Vendor staff change, and old credentials stay active
A vendor with weak security can be compromised, which exposes every client they connect to
Access is often broader than the task requires
Under HIPAA, vendors that can reach PHI are business associates, and you remain responsible for ensuring appropriate safeguards and agreements are in place.
Start by finding out who has access today. Check:
Remote access software installed on servers and workstations
Firewall rules and VPN accounts
Accounts in your directory that belong to vendors
Accounts inside applications such as the EMR
Cloud portals and administrative consoles
Devices with vendor-managed remote connectivity, such as cellular modems on building systems
Ask each department head which vendors they work with, since IT may not know about everything.
Before a vendor connects, confirm that:
A business associate agreement is in place if PHI may be accessible
The contract describes expectations for security and incident reporting
The vendor uses multi-factor authentication for their own staff and for access to your environment
Individual vendor technicians have their own credentials
Do not hand over administrator rights because it is faster.
Create separate accounts for each vendor, with only the permissions needed
Restrict access to specific systems, rather than the entire network
Limit connections by time, such as enabling access only during an agreed maintenance window
Use a controlled gateway, such as a VPN with multi-factor authentication or a privileged access tool that records sessions
Set a simple process. The vendor requests access, an internal owner approves it, IT enables it and then disables it after the work is done. Maintain a log of when access occurred, who connected and what was done. Session recording, where available, provides strong accountability for high-risk systems.
Permanent unattended access is convenient and dangerous. Where possible, require a staff member to approve each connection, or use tools that generate one-time sessions. If a vendor insists on standing access, document the reason, compensate with extra controls and review it regularly.
On a schedule, such as quarterly, review:
The list of vendor accounts and remote connections
When each was last used
Whether the vendor relationship is still active
Whether permissions still match the work being done
Disable anything not used recently, and delete accounts for vendors that no longer work with you. Reviewing firewall rules and remote tools at the same time can reveal forgotten pathways.
When a contract ends, a project finishes or an employee at the vendor leaves, remove access promptly. Add a step to your contract termination checklist for revoking credentials, deleting remote software and retrieving equipment.
Some devices come with built-in vendor connectivity, such as a cellular link or a cloud management portal. Understand how these work and place the devices on isolated network segments.
Your IT provider typically has the broadest access of all, so hold them to the highest standard. Ask how they protect administrator credentials, whether they use separate accounts per technician and how they log activity.
Vendors may need to connect urgently outside business hours. Define an emergency procedure with a named approver and phone number, so the pressure of an outage does not lead to unsafe shortcuts.
How do your technicians authenticate when connecting to us?
Are sessions logged, and can we see the logs?
What would you do if one of your employee accounts were compromised?
How quickly will you notify us of a security incident?
UnityCare IT helps healthcare organizations inventory third-party access, set up controlled remote access with multi-factor authentication and run periodic reviews. If you are not sure who can connect to your network today, an access inventory is a good first project.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172