Remote Work Security: What Regulated Practices Need to Know

Blog Image

Remote and hybrid work is now a permanent part of how many medical practices, law firms, and financial advisory offices operate. But your compliance obligations don’t change based on where your staff sit. HIPAA, PCI-DSS, and Massachusetts data security requirements apply whether someone is working at a hospital-grade workstation or from a kitchen table. The risks just look different — and they require a different set of controls.

Your Compliance Obligations Follow Your Staff

Under HIPAA, the covered entity — your practice — is responsible for maintaining appropriate safeguards for Protected Health Information regardless of where that information is accessed. The Security Rule applies to electronic PHI accessed from any device, on any network. If a staff member opens a patient record from home on an unmanaged laptop over an unsecured home network, your practice bears responsibility for what happens to that data. The location of the access doesn’t limit your liability.

Home Networks Are Not Office Networks

A typical home router runs with default settings, a rarely-updated firmware, and a shared network that includes streaming devices, gaming consoles, and whatever else the household uses. That environment is fundamentally different from a managed office network with monitored traffic, access controls, and regular patching. Minimum steps to reduce exposure on home networks include:

  • Requiring a VPN for all access to practice systems — this creates an encrypted tunnel between the remote device and your network, reducing exposure on whatever network the employee is using

  • Advising staff to ensure their home router firmware is current and that the router uses WPA2 or WPA3 encryption — not open or WEP-protected networks

  • Prohibiting the use of public Wi-Fi (coffee shops, libraries, airports) for accessing any patient or client records, even over a VPN

Device Management — Who Owns the Device Matters

Bring-your-own-device (BYOD) arrangements are common in smaller practices but carry real compliance risk. A personal device running outdated software, without full disk encryption, sharing an iCloud account with family members, is not an appropriate device for accessing PHI or privileged client data. Practices that allow staff to work on personal devices should at minimum:

  • Require that any device used to access practice systems has full disk encryption enabled (BitLocker on Windows, FileVault on macOS)

  • Enforce automatic screen lock after a short idle period and require a strong PIN or passphrase

  • Maintain the ability to remotely wipe the device if it is lost or stolen — this requires enrollment in a mobile device management (MDM) solution or equivalent

  • Keep operating systems, browsers, and any practice software current — unpatched personal devices are a common entry point for attackers

Remote Access Controls

Two controls that should be non-negotiable for any practice with remote staff: a VPN and multi-factor authentication (MFA). A VPN alone is not sufficient — if an attacker obtains a staff member’s password, VPN access doesn’t stop them. MFA requires a second verification step (a code sent to a phone or generated by an app) that makes credential theft significantly less useful. Enable MFA on:

  • Practice email (this is often the entry point for phishing and business email compromise)

  • Your EHR, practice management, or case management system

  • Any cloud storage or file-sharing service used for client or patient files

  • VPN access itself, if your provider supports it

The Physical Dimension of Remote Work

Data security at home is not just a software problem. Staff working in shared living spaces, on calls about patient or client matters, or leaving screens visible to household members are creating exposure that no technical control fully addresses. Practical guidance to include in your remote work policy:

  • Take calls involving PHI or privileged client information in a private space, not in common areas

  • Position monitors so they cannot be viewed by others in the household

  • Do not print patient or client records at home unless there is a secure disposal process in place for those documents

  • Log out of practice systems completely when a work session ends — do not rely on browser autofill or saved sessions on shared devices

Your Remote Work Policy Needs to Actually Exist

Many practices that have allowed remote or hybrid work for several years still have no formal written remote work security policy. HIPAA’s administrative safeguard requirements expect covered entities to have documented policies governing how PHI is accessed, by whom, and under what conditions. If a regulator or auditor asks for your remote access policy and you don’t have one, that gap becomes part of the finding. A basic policy should document acceptable devices and network configurations, required security controls, expectations for physical security of data, and the process for reporting a lost or compromised device.

If your practice has staff working remotely and you haven’t formally assessed those risks or documented your controls, a compliance review is a practical starting point. Getting this right before an audit — or an incident — is considerably easier than addressing it after.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.

Shape

Direct Access, Real Answers.

Not Sure Where to Start? Let’s Find Out Together.

Most practices don’t know their actual risk exposure until someone looks. A free consultation tells you exactly where you stand — no commitment, no pressure.