Think about everyone who can reach your network without walking through the front door. The EHR vendor's support team. The company that maintains your phone system. The manufacturer of a medication dispensing cabinet. A security camera installer. A copier service. Each may have a remote tool installed, a VPN account or a permanently open firewall rule that someone set up years ago and nobody remembers.
Third-party access is one of the most overlooked sources of risk in healthcare, because it is convenient, necessary and rarely reviewed.
Attackers often prefer to compromise a smaller vendor and use its trusted connection to reach many customers. Even without a malicious vendor, risks include shared passwords, outdated remote tools and access that stays on long after a project ends.
From a HIPAA perspective, vendors who can access protected health information are generally business associates and need a signed agreement. Even vendors who do not intentionally touch PHI, such as a device maintenance company, can reach it if access is not restricted.
Create a simple table with these columns:
Vendor name and purpose
Systems they can reach
How they connect: VPN, remote desktop tool, always-on agent, firewall rule
Who approved it and when
Whether a business associate agreement is in place
Whether they use individual accounts or a shared login
Whether multi-factor authentication is required
Review date
Check your firewall rules, VPN user list, remote support software and server accounts. The goal is to find connections nobody remembered.
Vendors should only reach what they need.
Restrict access to the specific servers or devices they support, not the whole network
Put medical and building systems in their own network segments
Use time-limited access where possible, enabled only during scheduled maintenance windows
Give each vendor technician an individual account so activity is traceable
Shared vendor passwords are a common weakness. Ask each vendor to:
Use individual named accounts
Support multi-factor authentication
Notify you when staff leave their company
If a vendor cannot meet those basics, consider whether a different arrangement or a different vendor makes more sense.
Use a single approved remote access method rather than allowing every vendor to bring its own software. This simplifies logging and reduces the number of tools to patch. Where possible:
Require the vendor to request access, with staff approving each session
Record or log sessions on sensitive systems
Disable remote tools when not in use
Agreements with vendors should address:
A business associate agreement where PHI may be accessed
Security expectations such as MFA, patching and employee screening
Breach notification: how quickly they must tell you about an incident on their side
What happens to your data at the end of the relationship
Right to review security documentation
Schedule a review at least once a year and whenever a contract ends. Remove accounts, close firewall rules and uninstall remote tools for vendors you no longer use. Include this step in your offboarding checklist for vendor relationships, just as you would for employees.
How will your staff connect to our systems?
Do your technicians use individual accounts and MFA?
How do you protect your own network and employee laptops?
Have you had a security incident in the past, and how did you respond?
Will you sign a business associate agreement?
How will you notify us of a security incident?
Answers do not need to be perfect, but evasive answers tell you something.
Leaving a vendor VPN active after installation
Allowing remote tools to run unattended on servers
Sharing the same administrator password across several vendors
Not knowing which devices, such as copiers or thermostats, are internet connected
Treating a verbal assurance as a substitute for a written agreement
A vendor access review can often be done in a day or two for a single facility and typically uncovers several connections nobody needed. UnityCare IT can help inventory your third-party connections, tighten them and document the results for your compliance records.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172