Vendor Remote Access: Who Is Connecting to Your Network?

Think about everyone who can reach your network without walking through the front door. The EHR vendor's support team. The company that maintains your phone system. The manufacturer of a medication dispensing cabinet. A security camera installer. A copier service. Each may have a remote tool installed, a VPN account or a permanently open firewall rule that someone set up years ago and nobody remembers.

Third-party access is one of the most overlooked sources of risk in healthcare, because it is convenient, necessary and rarely reviewed.

Why vendor access is risky

Attackers often prefer to compromise a smaller vendor and use its trusted connection to reach many customers. Even without a malicious vendor, risks include shared passwords, outdated remote tools and access that stays on long after a project ends.

From a HIPAA perspective, vendors who can access protected health information are generally business associates and need a signed agreement. Even vendors who do not intentionally touch PHI, such as a device maintenance company, can reach it if access is not restricted.

Step 1: Build a vendor access inventory

Create a simple table with these columns:

Vendor name and purpose

Systems they can reach

How they connect: VPN, remote desktop tool, always-on agent, firewall rule

Who approved it and when

Whether a business associate agreement is in place

Whether they use individual accounts or a shared login

Whether multi-factor authentication is required

Review date

Check your firewall rules, VPN user list, remote support software and server accounts. The goal is to find connections nobody remembered.

Step 2: Apply least privilege

Vendors should only reach what they need.

Restrict access to the specific servers or devices they support, not the whole network

Put medical and building systems in their own network segments

Use time-limited access where possible, enabled only during scheduled maintenance windows

Give each vendor technician an individual account so activity is traceable

Step 3: Require strong authentication

Shared vendor passwords are a common weakness. Ask each vendor to:

Use individual named accounts

Support multi-factor authentication

Notify you when staff leave their company

If a vendor cannot meet those basics, consider whether a different arrangement or a different vendor makes more sense.

Step 4: Control the session

Use a single approved remote access method rather than allowing every vendor to bring its own software. This simplifies logging and reduces the number of tools to patch. Where possible:

Require the vendor to request access, with staff approving each session

Record or log sessions on sensitive systems

Disable remote tools when not in use

Step 5: Put it in the contract

Agreements with vendors should address:

A business associate agreement where PHI may be accessed

Security expectations such as MFA, patching and employee screening

Breach notification: how quickly they must tell you about an incident on their side

What happens to your data at the end of the relationship

Right to review security documentation

Step 6: Review regularly

Schedule a review at least once a year and whenever a contract ends. Remove accounts, close firewall rules and uninstall remote tools for vendors you no longer use. Include this step in your offboarding checklist for vendor relationships, just as you would for employees.

Questions to ask a new vendor

How will your staff connect to our systems?

Do your technicians use individual accounts and MFA?

How do you protect your own network and employee laptops?

Have you had a security incident in the past, and how did you respond?

Will you sign a business associate agreement?

How will you notify us of a security incident?

Answers do not need to be perfect, but evasive answers tell you something.

Common mistakes

Leaving a vendor VPN active after installation

Allowing remote tools to run unattended on servers

Sharing the same administrator password across several vendors

Not knowing which devices, such as copiers or thermostats, are internet connected

Treating a verbal assurance as a substitute for a written agreement

Getting help

A vendor access review can often be done in a day or two for a single facility and typically uncovers several connections nobody needed. UnityCare IT can help inventory your third-party connections, tighten them and document the results for your compliance records.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172