By "open on their router" I assume you mean open to the Internet. I'd advise against this. Remote Desktop Protocol is susceptible to known attacks. Also you say "patched", but even as recently as last week Microsoft issued a security bulletin against RDP:
This security update resolves two privately reported vulnerabilities
in the Remote Desktop Protocol. The more severe of these
vulnerabilities could allow remote code execution if an attacker sends
a sequence of specially crafted RDP packets to an affected system.
I would strongly recommend putting some kind of security gateway (e.g. authenticated firewall, VPN...) in between users and the RDP service.