A small healthcare practice may rely on a compact team, outsourced IT, cloud applications, and remote support to keep patient care moving. That convenience also creates important access questions: Who can administer the electronic health record? Which vendor can reach a workstation after hours? Does the same account handle ordinary email and system administration? Can a remote desktop service be reached directly from the internet?

The current HHS cybersecurity practices for small healthcare organizations give unusually direct answers. The access-management section recommends identifying users, maintaining access audit trails, tailoring access to workplace needs, using MFA, separating elevated administrator accounts from routine accounts, requiring MFA for VPN access, disabling inbound Remote Desktop Protocol (RDP), and implementing procedures that consistently provision and monitor access.

This is a cybersecurity checklist, not a compliance determination. HHS says HIPAA risk analysis is foundational, but its guidance does not prescribe a one-size-fits-all method. The appropriate safeguards depend on the regulated organization's own environment and risks. This article is general technical guidance and not legal advice.

Why privileged access deserves separate attention

Privileged accounts can create users, change security settings, access broad collections of information, alter backups, or administer systems. In a medical practice, those identities may belong to an employee, an outside IT provider, an application vendor, or a software service rather than a full-time security team.

For a broader small-business approach to these identities, see our Tennessee playbook for privileged access.

HHS's small-organization guide notes that many small healthcare organizations use third-party IT and cloud providers. That makes access ownership especially important: outsourcing the work does not answer who approved the access, how much access was granted, when it should end, or what activity can be reviewed.

A six-part access checklist

Use these controls as inputs to your organization's risk analysis and implementation plan. Open each item for practical review questions.

1. Give each person a unique identity

HHS recommends clearly identifying users and maintaining audit trails for access to data, applications, systems, and endpoints. Shared logins weaken that accountability because a record may show what an account did without showing which person used it.

  • Assign individual accounts for staff, clinicians, contractors, and support personnel wherever the system permits.
  • Identify shared or generic accounts and document why they still exist.
  • Confirm that important applications and remote-support tools produce usable access logs.
  • Give each account an owner who is responsible for approving and reviewing it.
2. Give administrators two accounts

HHS specifically recommends issuing system administrators one account with elevated privileges and another for routine office functions. The privileged account should be reserved for essential administrative operations, with its exposure to email and social media limited.

For an internal administrator or outside IT technician, use a named everyday account for email, documentation, and ordinary work. Use a separate named administrative identity only when elevation is required. Do not make the routine account a permanent local administrator merely for convenience.

3. Match access to the person's actual job

HHS recommends tailoring access to each user's workplace requirements. A scheduler, biller, clinician, practice manager, and IT provider do not necessarily need the same information or system functions.

  • Start with the minimum role that supports the person's work, then approve exceptions deliberately.
  • Limit vendor access to the systems and time periods needed for support.
  • Avoid giving broad administrative roles to solve one narrow task.
  • Review sensitive functions such as account creation, audit-log changes, exports, backups, and security configuration separately.
4. Make onboarding, changes, and offboarding repeatable

HHS recommends access-management procedures that promote consistent provisioning and control. Turn that recommendation into a short lifecycle: request, approve, provision, review, change, and revoke.

Connect access changes to hiring, role transfers, extended leave, contract expiration, and departure. Include cloud applications, remote-support products, door or badge systems where relevant, vendor portals, and any credentials retained by an outside provider. Record who approved elevated access and set a review or expiration date.

5. Require MFA for sensitive, privileged, and remote access

HHS recommends MFA for areas containing sensitive information and for VPN connections to on-premises or cloud systems. NIST's small-business MFA guidance explains that MFA adds another barrier if a password is compromised and that some methods resist phishing better than one-time codes or SMS.

Prioritize EHR and practice-management administrators, cloud email administrators, VPNs, remote-support tools, backup consoles, identity systems, and password vaults. Where supported and practical, evaluate phishing-resistant methods such as security keys or passkeys for elevated users. Keep recovery and enrollment processes controlled so they do not become easier paths around MFA.

6. Remove open inbound RDP and monitor remote access

HHS advises small healthcare organizations to disable inbound RDP on internal systems and instead use a VPN tunnel for the specific users and systems that require remote connections. Its January 2026 cybersecurity newsletter also advises regulated entities to consider disabling or blocking insecure uses of remote-access services such as RDP.

The same layered principles also apply to industrial environments; our guide to securing remote SCADA and PLC access explains how direct exposure can create operational risk.

  • Determine whether TCP port 3389 or another RDP mapping is exposed from the public internet.
  • Inventory remote-support agents, VPN accounts, vendor gateways, and unattended-access configurations.
  • Require named accounts and MFA; restrict which systems each remote identity can reach.
  • Log connections and review unusual source locations, after-hours access, failed authentication, and new administrative assignments.
  • Remove dormant vendor access rather than leaving it available for a possible future support call.

Put the checklist inside your risk analysis

HHS Office for Civil Rights guidance states that risk analysis is the first step in identifying and implementing safeguards under the HIPAA Security Rule. It also emphasizes that the process is not a one-size-fits-all blueprint.

The current HHS Security Risk Assessment Tool is designed to help small and medium providers conduct that analysis. HHS expressly warns that using the tool is neither required nor a guarantee of compliance, and that it is not legal advice. That is the right way to view this checklist too: as a structured way to find and prioritize access risks, not as a compliance certificate.

Organizations that need help organizing findings, ownership, and remediation priorities can use fractional CISO support to turn a risk review into a practical security program.

A practical first review

Choose the systems that contain sensitive information or could interrupt patient care. For each one, list its administrators, vendors, service identities, remote-access paths, MFA status, and logging capability. Remove access with no current owner or business purpose, then assign dates for the remaining gaps.

The goal is not to buy the largest possible security platform. It is to make elevated access limited, attributable, strongly authenticated, reviewable, and removable. A small practice can begin that work with an inventory and a disciplined process, then add vaulting, credential rotation, approval workflows, or session monitoring where risk and complexity justify them.

Need Help Reviewing Privileged Access?

West Tennessee Software Solutions can help healthcare practices inventory administrative and vendor access, identify priority gaps, and design right-sized credential controls.

Explore Our PAM Services