Educause Security Discussion mailing list archives

Re: Home Access


From: David Grisham <DGrisham () SALUD UNM EDU>
Date: Fri, 4 Nov 2005 15:50:47 -0700

How if at all does anyone give home access to workers from the health science center & university hospital?  HIPAA has 
a specific workstation security implementation specification that requires the institution to ensure that workstations 
accessing Electronic Protected Health Information (ePHI) be secure.  We can make sure that our workstations have the 
latest security patches, firewalls & up to date anti virus software.  We currently loan secure images to our home 
transcriptionists.  However, Internet access is here and our medical staff does need to work from home or from other 
sites with Internet access.
 
I would be glad to talk with anyone from any institution who was considering a portal, Internet access or just home 
access to ePHI and what we're doing to ensure that our workforce does not open up patient records at Starbucks, walk 
away from a screen in a public area, or use any workstation that does not meet are minimum security requirements.
 
 
Cheers. -grish
David D. Grisham, Ph.D.,  CISM, CHS III
Manager, IT Security,
UNM Hospitals, Information Technology
1650 University Blvd,  S.500, Albuquerque, NM 87102
Ph: (505) 272-5657 FAX 272-3305
Work email:  dgrisham () salud unm edu
Adjunct Faculty, Computer Science, UNM
Academic & personal email:  dave () unm edu
 

vphung () SCIENCE SJSU EDU 11/4/2005 2:46:22 PM >>>

For remote access

Email - webmail with SSL v3 only
Web related - WebDAV with SSL v3 only
All others - Remote desktop via tunnel using SSH v2 only

SSH tunneling works really well with either VNC (Mac and *NIX) or RDC (Windows) from home (DSL for better performance). 
It's easy to implement and required almost no maintenance since most of us has an SSH server somewhere on a network 
where a user's computer can be reached. Instruction is here

http://ncs.science.sjsu.edu/vphung/index.php?HOW_TO:RDC

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vuong Phung
Operating Systems Administrator
College of Science - Dean's Office

San Jose State University
One Washington Square
San Jose, CA 95192-0099
Duncan Hall 33

Tel 1.408.924.5056
Fax 1.408.924.5033
Web http://ncs.science.sjsu.edu/helpdesk
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

-----Original Message-----
From: clementz.7 [mailto:clementz.7 () OSU EDU]
Sent: Friday, November 04, 2005 12:02 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Home Access


How many schools allow remote access and what types of access do you allow.  Please email me directly and I will give 
you my phone number to talk more securly.
.  We have faculty that are pushing more and more for remote access, but we do not have the manpower to support it.  
Just curious if others are experiencing the same issues.

Todd Clementz
Systems Administrator
The Austin E. Knowlton School of Architecture
The Ohio State University
Support Site.  http://support.knowlton.ohio-state.edu
clementz.7 () osu edu



Current thread: