# How to secure Openemr the easy way - Noob Advice

**URL:** <https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774>\
**Category:** Security\
**Tags:** question\
**Created:** [January 10, 2021, 9:36pm UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774 "2021-01-10T21:36:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohamed](https://community.open-emr.org/letter_avatar_proxy/v4/letter/m/d78d45/32.png) [@mohamed](https://community.open-emr.org/u/mohamed)\
**Post date:** [January 10, 2021, 9:36pm UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/1 "2021-01-10T21:36:31Z")

</div>

I am running Xampp on win 10. How to secure Openemr the easy way ? I already read the wiki and did the steps I could do on my own, some steps seem complicated. I don’t have a dedicated server at hand. Limited number of users. The computer is connected to the internet, but not powered on 24/7.

Here is what I have done:  
1-Strong passwords in Openemr  
2-2FA for Openemr users.  
3-Installed Xampp on another drive than C drive, and bit-locked encrypted the drive as well as the back up drive. The computer is encrypted, UPS protected and physically locked in a safe place.  
4-My LAN has a WIFI router with AES strong passwords, MAC filtering, and no port forwarding. No physical access to router.  
5-Will not use portal.  
6-Still trying how use https, especially on mobile phones and iPad’s.  
7-Access control is very limited to users, each within his scope.  
8-The Xampp configuration is set to listen to my IP range only.  
9-Still trying to choose my best daily back-up method.  
10-My windows installation is pretty okay in security and privacy, computer will be running in a local standard user account, but I don’t know if I will need using a firewall software.  
11-Windows, Xampp, and Openemr will always be regularly patched.

Will it survive ?

---

<div class="post-metadata">

**Author:** ![mohamed](https://community.open-emr.org/letter_avatar_proxy/v4/letter/m/d78d45/32.png) [@mohamed](https://community.open-emr.org/u/mohamed)\
**Post date:** [January 21, 2021, 3:39pm UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/2 "2021-01-21T15:39:13Z")

</div>

Anybody has ideas regarding the before mentioned steps to secure Openemr ? Any major problems using internet while Xampp is working ? Any security advice is appreciated.

---

<div class="post-metadata">

**Author:** ![brady.miller](https://community.open-emr.org/user_avatar/community.open-emr.org/brady.miller/32/10178_2.png) [@brady.miller](https://community.open-emr.org/u/brady.miller)\
**Post date:** [January 22, 2021, 7:23am UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/3 "2021-01-22T07:23:42Z")

</div>

Could also add apache ssl client certificates (a nice layer of security at a higher apache level). Can check out Administration-\>System-\>Certificates for details on creating ssl certs and client side ssl certificates. (using client certificates would mean that only users that add the client ssl certificates on their browser would be able to get to OpenEMR)

---

<div class="post-metadata">

**Author:** ![brady.miller](https://community.open-emr.org/user_avatar/community.open-emr.org/brady.miller/32/10178_2.png) [@brady.miller](https://community.open-emr.org/u/brady.miller)\
**Post date:** [January 22, 2021, 7:24am UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/4 "2021-01-22T07:24:50Z")

</div>

And definitely ensure all communication is done via https(ie. ssl).

---

<div class="post-metadata">

**Author:** ![mohamed](https://community.open-emr.org/letter_avatar_proxy/v4/letter/m/d78d45/32.png) [@mohamed](https://community.open-emr.org/u/mohamed)\
**Post date:** [January 22, 2021, 7:34am UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/5 "2021-01-22T07:34:41Z")

</div>

Thanks for your reply. Generating ssl certificates is not my ballpark, but I will keep trying till I figure it out. But will it be applicable on mobile phones and iPad.

---

<div class="post-metadata">

**Author:** ![brady.miller](https://community.open-emr.org/user_avatar/community.open-emr.org/brady.miller/32/10178_2.png) [@brady.miller](https://community.open-emr.org/u/brady.miller)\
**Post date:** [January 22, 2021, 7:39am UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/6 "2021-01-22T07:39:57Z")

</div>

Yes, follow that script I linked to in OpenEMR. That is actually a good intro into creating ssl certs and what to do with them. The client sides certs can be installed on any web browser on any device.

---

<div class="post-metadata">

**Author:** ![mohamed](https://community.open-emr.org/letter_avatar_proxy/v4/letter/m/d78d45/32.png) [@mohamed](https://community.open-emr.org/u/mohamed)\
**Post date:** [January 22, 2021, 7:55am UTC](https://community.open-emr.org/t/how-to-secure-openemr-the-easy-way-noob-advice/15774/7 "2021-01-22T07:55:11Z")

</div>

Will do and will post here again when successful.
