Does anyone allow campus health center staff remote acces via VPN to their patient records systems? If so, what requirements/guidelines to you use to insure the end point is secure beyond just using a secure connection?


We do allow remote access.  To access the EHR, one must first use the campus VPN system.  Secondly, they must use the Citrix system to gain access to the application or a remote desktop.  Even then, only select personnel are enabled for remote access to the EHR according to their business need.


I’d love to require a specific, controlled end point to use, such as a health-center issued laptop (for business use only) or perhaps even better, a thin client device or locked-down tablet or netbook.  The reality is that once remote access is given, any client can connect – at least that is the current reality with our campus VPN technology.


We encourage our staff to use health computers to connect and remind them that if their home system is compromised and used to connect, it could expose the University to a disaster.


Thanks for the response. We do have a Citrix system as well and that wasn't a posible solution I had considered. It would keep the end point a managed system we know the security posture of but allow viewing/editing. 

I'd like to require use a university managed device as the ultimate end point as well.