How Remote Access is Creating HIPAA Vulnerabilities in South Florida Medical Practices
- Anthony Lauria

- Jul 15
- 6 min read

Remote work changed everything about how medical practices operate — and not all of those changes were managed with the same care as the clinical decisions the practices make every day.
Physicians reviewing patient records from home between evening calls. Billing staff completing claims from a home office. Practice managers accessing scheduling systems from a mobile device while running errands. Medical assistants checking in remotely when they're covering for a colleague at another location. These are all normal parts of how independent medical practices in Palm Beach County operate in 2026 — and each one represents a potential HIPAA vulnerability if the remote access isn't properly secured.
I've been doing healthcare IT exclusively for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie for 25 years. Remote access vulnerabilities are now one of the most consistent findings when I evaluate a new practice. Here's what those vulnerabilities look like, why they matter, and what properly secured remote access actually requires.
Why remote access is the most exploited entry point in healthcare
Healthcare has become the most targeted industry for cyberattacks, and remote access is the most common entry point. The reason is straightforward: remote access connects a protected system — your EMR, your clinical workstations, your patient data — to the open internet. Every connection is a potential door. The question is whether that door is properly locked.
The attacks that exploit remote access vulnerabilities in healthcare are not random. They're targeted and methodical. Attackers use credential stuffing — trying username and password combinations from other breaches against your systems — because healthcare staff reuse passwords at high rates. They use phishing specifically designed to capture healthcare credentials. They scan for known vulnerabilities in remote access tools and exploit them before patches are applied. And they use stolen credentials to establish persistent access — sitting inside a practice's network for weeks or months before activating the ransomware or exfiltrating the data that makes the attack profitable.
The average time between initial compromise and breach detection in healthcare is 279 days. That's nine months of an attacker having access to your patient records, your billing system, and your network infrastructure — while your practice operates normally, unaware.
The five most common remote access vulnerabilities in South Florida medical practices
1. No multi-factor authentication on remote access.
This is the single most common and most consequential remote access vulnerability I find. A username and password alone is not adequate protection for remote access to a system containing protected health information. Passwords get stolen — through phishing, through credential stuffing, through data breaches at other services where your staff reuses the same password. MFA means that a stolen password alone isn't enough to get in.
Under the 2026 HIPAA Security Rule updates, MFA for remote access to systems containing ePHI is effectively mandatory. The "addressable" flexibility that some practices used to defer MFA implementation is gone. If your remote access doesn't require MFA, you have a compliance gap and a security gap simultaneously.
2. Personal devices without management controls.
When a physician checks patient records from their personal iPhone, or a billing staff member accesses the practice management system from their home laptop, those personal devices become part of your security perimeter — whether you've secured them or not.
A personal device that isn't enrolled in a mobile device management system has no enforced encryption, no remote wipe capability if it's lost or stolen, no guarantee that it's running current software, and no visibility for your IT provider. If that device is compromised — through malware, through a stolen or lost device, through a family member using it — the attacker has the same access to your systems that the device's owner has.
3. Consumer-grade VPN or no VPN at all.
Virtual Private Networks encrypt the connection between a remote device and your network. Consumer-grade VPN products — the kind advertised for privacy and streaming — are not the same as enterprise VPN solutions designed for secure business access. They don't provide the authentication controls, the logging, the session management, or the administrative oversight that a properly secured remote access solution requires.
Many independent medical practices I evaluate have staff accessing practice systems either through consumer VPNs or with no VPN at all — using direct internet connections to web-based EMR portals that, while encrypted in transit, offer no protection against credential theft or session hijacking.
4. Unmonitored remote access sessions.
Knowing who accessed your systems remotely, when, from where, and what they did is both a HIPAA audit control requirement and an essential security capability. Without monitoring, you have no way to detect when a legitimate credential is being used maliciously — by an attacker who stole it, or by a staff member who is accessing records they shouldn't be accessing.
Most independent medical practices I evaluate have remote access logs that exist — they're being generated somewhere — but are not being reviewed, not being alerted on, and not being retained for the required period. The logs are there. No one is looking at them.
5. Remote access for former employees not revoked promptly.
Staff turnover is a consistent remote access risk. When a staff member leaves — voluntarily or otherwise — their remote access credentials should be revoked before they walk out the door, not after. In practice, remote access revocation is often delayed — by days, weeks, or in some cases indefinitely — because there's no formal offboarding process that includes IT access review.
A former employee with active remote access credentials to your EMR and your practice network is an insider threat risk regardless of how the employment ended. This is one of the most consistently underestimated vulnerabilities in independent medical practices.
What HIPAA actually requires for remote access
The HIPAA Security Rule's technical safeguard requirements apply fully to remote access — not just to on-site access. The access control standard requires unique user identification, emergency access procedures, automatic logoff, and encryption and decryption of ePHI. The audit control standard requires mechanisms to record and examine activity in systems containing ePHI — including remote access sessions. The transmission security standard requires encryption of ePHI in transit — which applies to every remote access connection.
The 2026 rule updates tightened these requirements by eliminating the addressable flexibility that some practices used to defer implementation. Remote access to ePHI now requires documented access controls, logged and monitored sessions, MFA, and encryption — without exception.
A practice that allows staff to access patient records remotely without these controls in place is not compliant with the HIPAA Security Rule. That's not a theoretical risk — it's a specific finding that OCR investigators look for when they investigate a breach that originated through remote access, which is now the majority of healthcare breaches.
What properly secured remote access looks like
Properly secured remote access for an independent medical practice in Palm Beach County has several components.
MFA on every remote access point. Every login to your EMR, your practice management system, your email, and any other system containing ePHI should require a second factor — an authentication app, a hardware token, or a push notification — in addition to a password.
Mobile device management for every device that accesses practice systems. Every device — physician smartphones, tablets, home laptops — that accesses your practice systems should be enrolled in an MDM platform that enforces encryption, enables remote wipe, maintains current software versions, and provides your IT provider with visibility into the device's security posture.
An enterprise remote access solution with logging. Not a consumer VPN. An enterprise remote access tool that requires authentication, logs sessions, enables session monitoring, and provides your IT provider with the visibility to detect anomalous access patterns.
A SIEM integrating remote access logs. Remote access logs need to be collected into a SIEM alongside logs from your network, your workstations, and your EMR — so that patterns that don't trigger alerts in any individual log can be detected through cross-environment correlation.
A formal access provisioning and deprovisioning process. Every remote access credential should be documented, reviewed periodically, and revoked promptly when a staff member's role changes or employment ends.
The South Florida specific dimension
Remote access security has a specific dimension for practices in South Florida that practices in other markets don't face as acutely: hurricane season.
When a major storm forces practice closure — or forces staff to work from non-standard locations for extended periods — remote access becomes not just convenient but operationally critical. Practices that haven't secured their remote access infrastructure are in the position of either allowing unsecured access during a crisis or losing operational continuity entirely.
The right time to secure remote access is before hurricane season, not during a storm when your staff is scattered across different locations and your IT provider is managing multiple client emergencies simultaneously.
Where to start
If you're an independent medical practice in Palm Beach County and you're not certain your remote access is properly secured, the right starting point is an honest assessment of what you actually have in place.
Skyline Technology offers a complimentary HIPAA IT Risk Assessment for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie. It specifically covers remote access security as part of a six-category review and produces a written summary with prioritized recommendations — yours to keep with no obligation.
Anthony Lauria is the founder of Skyline Technology, a Palm Beach Gardens-based managed IT provider serving dental and medical practices exclusively across Palm Beach, Martin, and St. Lucie counties. He has been in IT since 2000 and has lived in Palm Beach Gardens since 2001.
Request a complimentary HIPAA IT Risk Assessment at skyline.technology/hipaa-assessment or call or text (561) 316-8665.


