Imagine pulling a list of everyone who can log into your EMR and discovering names of employees who left a year ago, a traveling nurse whose contract ended last spring, and a manager who moved to a different department but still has billing permissions. This is common. Access accumulates as people join, change roles and leave, and nobody goes back to clean it up.
Regular access reviews fix the problem. They are simple in concept, they are one of the most useful security habits a care organization can adopt, and they support several HIPAA requirements, including workforce clearance, access authorization, and information system activity review.
Unused accounts are rarely watched. If an attacker takes over a dormant account, nobody notices unusual behavior.
Former employees may retain access, which creates risk of intentional misuse or retaliation.
Excess permissions amplify mistakes. An employee with broad access can accidentally expose or delete far more data than one with limited rights.
Privilege creep happens when employees accumulate permissions over time as they take on new tasks, without losing old ones.
Auditors and insurers ask about it. Being able to show recent reviews is strong evidence of good practice.
Access exists in many places, not just the EMR. Build a list of systems that hold or connect to sensitive information.
The EMR and any connected clinical applications
Active Directory or the cloud identity system
Email and file sharing
Billing, payroll and HR applications
VPN and remote access tools
Cloud services and web portals, such as pharmacy, lab, payer and state reporting sites
Administrator accounts on servers, network devices and security tools
Shared and generic accounts
Vendor and contractor accounts
For each system, generate a list of accounts with their roles, last login dates and status. IT can often produce these quickly for systems under its control. For vendor-managed applications, ask the administrator or vendor for a report.
Match the lists against current employee and contractor rosters. Flag every account that does not match a current person. Pay particular attention to terminations, leaves of absence, agency staff and seasonal workers.
Send each department head the list of their staff and what they can access. Ask them to confirm, for each person, that the access is still appropriate. Keep the request simple, with clear choices: keep, change or remove. Set a deadline and follow up with those who do not respond.
Administrator access deserves closer attention. Review who holds it, why, whether it is separate from the person's everyday account, and whether multi-factor authentication is enforced. Reduce the number of administrators where possible.
Identify accounts that have not logged in for a defined period, such as 60 or 90 days. Disable them, and delete after a retention period if no longer needed. Some accounts, such as those used by staff on extended leave, may need to be temporarily disabled rather than removed.
Remove or adjust access, and keep records of the review: who performed it, the date, the findings and the corrections. This documentation is valuable during audits, investigations and insurance renewals.
Twice a year is a common target for clinical systems and privileged accounts. Higher-risk systems may justify quarterly reviews. In addition, trigger reviews for events like a reorganization, a merger or a security incident.
A review finds problems after the fact. Preventing them requires better processes.
Have HR notify IT of every hire, transfer and departure through a standard form or ticket
Disable access on the last day of employment, or sooner when appropriate
Use role-based access templates when creating accounts
Set expiration dates for contractor and agency accounts
Avoid shared logins, which obscure accountability
Use single sign-on where possible to centralize control
Access reviews pair well with a look at activity logs. Unusual patterns, such as someone viewing records of residents not on their unit, repeated failed login attempts or logins at odd hours, may signal misuse or compromise. Many EMR platforms provide audit reports, and your compliance officer can schedule regular reviews.
UnityCare IT helps healthcare organizations run access reviews, clean up accounts and build onboarding and offboarding processes that keep permissions accurate. If it has been more than six months since anyone checked, we can help you set up the first review.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172