The short answer NO. The long answer is it can be HIPAA compliant, PCI compliant and accepted as Standard Business Security if you use Remote Desktop (or RDP) across a VPN. We work with many healthcare providers and the HIPAA rules are pretty clear.
Any access from the Internet or a remote location must be encrypted.