Remote Work Security: What Regulated Practices Need to Know

Remote and hybrid work is now a permanent part of how many medical practices, law firms, and financial advisory offices operate. But your compliance obligations don’t change based on where your staff sit. HIPAA, PCI-DSS, and Massachusetts data security requirements apply whether someone is working at a hospital-grade workstation or from a kitchen table. The risks just look different — and they require a different set of controls.
Your Compliance Obligations Follow Your Staff
Under HIPAA, the covered entity — your practice — is responsible for maintaining appropriate safeguards for Protected Health Information regardless of where that information is accessed. The Security Rule applies to electronic PHI accessed from any device, on any network. If a staff member opens a patient record from home on an unmanaged laptop over an unsecured home network, your practice bears responsibility for what happens to that data. The location of the access doesn’t limit your liability.
Home Networks Are Not Office Networks
A typical home router runs with default settings, a rarely-updated firmware, and a shared network that includes streaming devices, gaming consoles, and whatever else the household uses. That environment is fundamentally different from a managed office network with monitored traffic, access controls, and regular patching. Minimum steps to reduce exposure on home networks include:
Requiring a VPN for all access to practice systems — this creates an encrypted tunnel between the remote device and your network, reducing exposure on whatever network the employee is using
Advising staff to ensure their home router firmware is current and that the router uses WPA2 or WPA3 encryption — not open or WEP-protected networks
Prohibiting the use of public Wi-Fi (coffee shops, libraries, airports) for accessing any patient or client records, even over a VPN
Device Management — Who Owns the Device Matters
Bring-your-own-device (BYOD) arrangements are common in smaller practices but carry real compliance risk. A personal device running outdated software, without full disk encryption, sharing an iCloud account with family members, is not an appropriate device for accessing PHI or privileged client data. Practices that allow staff to work on personal devices should at minimum:
Require that any device used to access practice systems has full disk encryption enabled (BitLocker on Windows, FileVault on macOS)
Enforce automatic screen lock after a short idle period and require a strong PIN or passphrase
Maintain the ability to remotely wipe the device if it is lost or stolen — this requires enrollment in a mobile device management (MDM) solution or equivalent
Keep operating systems, browsers, and any practice software current — unpatched personal devices are a common entry point for attackers
Remote Access Controls
Two controls that should be non-negotiable for any practice with remote staff: a VPN and multi-factor authentication (MFA). A VPN alone is not sufficient — if an attacker obtains a staff member’s password, VPN access doesn’t stop them. MFA requires a second verification step (a code sent to a phone or generated by an app) that makes credential theft significantly less useful. Enable MFA on:
Practice email (this is often the entry point for phishing and business email compromise)
Your EHR, practice management, or case management system
Any cloud storage or file-sharing service used for client or patient files
VPN access itself, if your provider supports it
The Physical Dimension of Remote Work
Data security at home is not just a software problem. Staff working in shared living spaces, on calls about patient or client matters, or leaving screens visible to household members are creating exposure that no technical control fully addresses. Practical guidance to include in your remote work policy:
Take calls involving PHI or privileged client information in a private space, not in common areas
Position monitors so they cannot be viewed by others in the household
Do not print patient or client records at home unless there is a secure disposal process in place for those documents
Log out of practice systems completely when a work session ends — do not rely on browser autofill or saved sessions on shared devices
Your Remote Work Policy Needs to Actually Exist
Many practices that have allowed remote or hybrid work for several years still have no formal written remote work security policy. HIPAA’s administrative safeguard requirements expect covered entities to have documented policies governing how PHI is accessed, by whom, and under what conditions. If a regulator or auditor asks for your remote access policy and you don’t have one, that gap becomes part of the finding. A basic policy should document acceptable devices and network configurations, required security controls, expectations for physical security of data, and the process for reporting a lost or compromised device.
If your practice has staff working remotely and you haven’t formally assessed those risks or documented your controls, a compliance review is a practical starting point. Getting this right before an audit — or an incident — is considerably easier than addressing it after.
Read other blogs
Stay informed with our latest articles on compliance, security, and risk management.


