Access Reviews: Who Still Has Login Rights to Resident Data?

Imagine pulling a list of everyone who can log into your EMR and discovering names of employees who left a year ago, a traveling nurse whose contract ended last spring, and a manager who moved to a different department but still has billing permissions. This is common. Access accumulates as people join, change roles and leave, and nobody goes back to clean it up.

Regular access reviews fix the problem. They are simple in concept, they are one of the most useful security habits a care organization can adopt, and they support several HIPAA requirements, including workforce clearance, access authorization, and information system activity review.

Why old access is dangerous

Unused accounts are rarely watched. If an attacker takes over a dormant account, nobody notices unusual behavior.

Former employees may retain access, which creates risk of intentional misuse or retaliation.

Excess permissions amplify mistakes. An employee with broad access can accidentally expose or delete far more data than one with limited rights.

Privilege creep happens when employees accumulate permissions over time as they take on new tasks, without losing old ones.

Auditors and insurers ask about it. Being able to show recent reviews is strong evidence of good practice.

What to review

Access exists in many places, not just the EMR. Build a list of systems that hold or connect to sensitive information.

The EMR and any connected clinical applications

Active Directory or the cloud identity system

Email and file sharing

Billing, payroll and HR applications

VPN and remote access tools

Cloud services and web portals, such as pharmacy, lab, payer and state reporting sites

Administrator accounts on servers, network devices and security tools

Shared and generic accounts

Vendor and contractor accounts

How to run a review

Step 1: Export user lists

For each system, generate a list of accounts with their roles, last login dates and status. IT can often produce these quickly for systems under its control. For vendor-managed applications, ask the administrator or vendor for a report.

Step 2: Compare against HR records

Match the lists against current employee and contractor rosters. Flag every account that does not match a current person. Pay particular attention to terminations, leaves of absence, agency staff and seasonal workers.

Step 3: Ask managers to confirm

Send each department head the list of their staff and what they can access. Ask them to confirm, for each person, that the access is still appropriate. Keep the request simple, with clear choices: keep, change or remove. Set a deadline and follow up with those who do not respond.

Step 4: Examine privileged accounts

Administrator access deserves closer attention. Review who holds it, why, whether it is separate from the person's everyday account, and whether multi-factor authentication is enforced. Reduce the number of administrators where possible.

Step 5: Look for dormant accounts

Identify accounts that have not logged in for a defined period, such as 60 or 90 days. Disable them, and delete after a retention period if no longer needed. Some accounts, such as those used by staff on extended leave, may need to be temporarily disabled rather than removed.

Step 6: Make the changes and document

Remove or adjust access, and keep records of the review: who performed it, the date, the findings and the corrections. This documentation is valuable during audits, investigations and insurance renewals.

How often

Twice a year is a common target for clinical systems and privileged accounts. Higher-risk systems may justify quarterly reviews. In addition, trigger reviews for events like a reorganization, a merger or a security incident.

Fix the process behind the problem

A review finds problems after the fact. Preventing them requires better processes.

Have HR notify IT of every hire, transfer and departure through a standard form or ticket

Disable access on the last day of employment, or sooner when appropriate

Use role-based access templates when creating accounts

Set expiration dates for contractor and agency accounts

Avoid shared logins, which obscure accountability

Use single sign-on where possible to centralize control

Review audit logs along with accounts

Access reviews pair well with a look at activity logs. Unusual patterns, such as someone viewing records of residents not on their unit, repeated failed login attempts or logins at odd hours, may signal misuse or compromise. Many EMR platforms provide audit reports, and your compliance officer can schedule regular reviews.

Getting started

UnityCare IT helps healthcare organizations run access reviews, clean up accounts and build onboarding and offboarding processes that keep permissions accurate. If it has been more than six months since anyone checked, we can help you set up the first review.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172