Context
The pattern behind the sector’s most damaging intrusions of the last two years is unglamorous: one stolen password, one remote-access portal that accepted it on its own, and nothing standing between the two.
The hospital knew this. It was in no way negligent. It had four people running every system in the building, and multi-factor authentication had sat on the list behind an EHR upgrade, a phone system migration and two staff departures. This is the ordinary situation at a small provider, and it is why the fix has to fit into the hours that actually exist.
Regulatory driver
HIPAA Section 164.312(a)(1) and (d) — access control and person-or-entity authentication — read against the OCR audit protocol, where the evidence sampled is how quickly access ends when someone leaves, whether emergency access is tested, and the audit controls under Section 164.312(b). Vendor access sits inside the BAA obligation, not outside it. The proposed Security Rule update would move multi-factor authentication from addressable to required; it is not final, so the work was scoped to what is in force today and built so that finalization changes nothing.
What we did
Remote access first, everything else later. Entra ID Conditional Access with phishing-resistant multi-factor authentication went in front of the Citrix portal before anything else was touched. Old authentication protocols that bypass it were switched off rather than monitored. This was the single change that answered the board’s question, and it went first for that reason.
Vendor accounts got boundaries. Eighteen third-party accounts held permanent access to the EHR well beyond what their contracts covered — the usual accumulation of software vendors, billing services and imaging partners. Each was checked against its BAA, cut back to what it actually needed, and given an expiry date. Vendors now re-confirm annually or the access lapses on its own.
Emergency access that actually works. Clinicians must be able to reach records in a crisis, and HIPAA requires the procedure to exist. It was rebuilt to expire on its own, raise an alert when used, and log everything — then tested with the clinical staff before it counted. Nobody gets locked out of a patient record because of a control we put in.
Result
Next audit: no patient-data findings. The answer to the board’s question is now no, and it can be shown rather than asserted, because the evidence is produced as the systems run instead of assembled afterwards.
Scope note: this was one workstream over six weeks, covering remote access, vendor accounts and emergency access. The four-person IT team runs it now; we wrote the runbook and left.