HIPAA Tip: Remote Access
What does remote access mean to you in your organization? For most businesses today remote access is a necessity. Whether it’s a physician who needs to review medical records after hours, a staff member who moved out of the area and is tasked with billing, or workforce members that may need to contact patients to reschedule appointments due to inclement weather.
- Always use multi-factor authentication (MFA) for secure remote access to ePHI
- Connect through Secure Sockets Layer Virtual Private Network (SSL VPN)
- Use 12-16 character passwords minimum (8-character passwords crack in minutes)
- Review remote access users regularly, disable unused accounts immediately
- Audit remote user activity regularly to monitor ePHI access
- Add remote access removal to Exit Interview Checklist
Very important reminders:
- How remote access is achieved is paramount. Always use two-factor (2FA) or multi-factor authentication (MFA) when connecting to systems and applications containing ePHI as the first step. Whether the connection is to the cloud or to the business servers, this needs to be through a Secure Sockets Layer Virtual Private Network (SSL VPN).
- Password length is key! An 8-character password can be cracked in as little as a few minutes. Why take the chance, especially when most of our personal accounts (banking, our own patient portal, retirement accounts), require 12–16-character passwords? This is an easy fix that costs no money to change yet secures the organization’s precious patient data.
- Review users that have remote access regularly. Is it possible due to unforeseen circumstances that multiple staff were set up with remote access and no longer need that connection? Be certain to add this to the Exit Interview Checklist and contact IT to disable immediately. Additionally, remote user activity must be audited on a regular basis. If this is not being conducted/completed how do you know who is in the systems and applications containing ePHI and whether it was necessary?
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.