I've found Google remote to be a little sluggish, and prefer the native Windows Remote Desktop.
To secure the connection, take a look at SoftEther VPN. It's Open Source, so if you run Windows Pro the whole setup won't cost a dime. You can restrict remote desktop connections to the LAN, and use Two Factor authentication (Duo Mobile) for extra protection.
Regarding HIPAA, I believe all of this is covered under the conduit exception rule, and so won't require a privacy agreement (much the same way that we don't all have privacy agreements with the US Postal service when we send medical records via snailmail.)