Instead of doing this... Please please please look at setting up a VPN... I would suggest one of the newer de-centralized options like Zerotier or Tailscale (especially if you do not have a static IP or have CGNAT)... But at minimal use Wireguard or OpenVPN with a dynamicDNS service. There will be clients for all platforms to connect, and you wont have to worry about having RDP open to the internet.
If your in healthcare then you know DONT OPEN RDP to the world... Its a HUGE attack surface.. You wont be able to pass any kind of accreditation/HIPPA security audit with an RDP port open, and I doubt you could even pass PCI... There is literally NO NEED FOR IT... Please use a VPN or some sort of de-centralized entry point.
Something like TeamViewer sounds like a fit here