In many small and mid-size organizations, administrator access has quietly spread. The office manager has it because she once needed to install a printer. The EMR super user has it because it was easier than setting precise permissions. A vendor has a permanent account created years ago. A manager's everyday login has full domain rights because that was how the previous IT person set things up.
Each of those accounts is a prize for an attacker. If a phishing email tricks someone with administrator rights, the intruder inherits those rights, and the damage can reach far beyond one computer.
The principle of least privilege says that every person, application and device should have only the access needed to do the job, and no more, for only as long as needed. It is a foundation of modern security frameworks, and it lines up with HIPAA's access control requirements and the minimum necessary concept.
Local administrator rights on workstations, which let users install software and make changes that malware can also exploit
Domain or global administrators in Windows environments or Microsoft 365
EMR super user and system administrator roles assigned broadly
Shared admin accounts known by several people, which prevent accountability
Service accounts used by applications, often with high privileges and passwords that never change
Vendor accounts with ongoing access and no expiration
Old accounts of former IT staff or consultants
Start with an inventory:
List all administrator accounts in your directory, email platform, firewall, wireless controller, backup system, EMR and key applications.
Identify the owner and purpose of each.
Note when each was last used.
Identify service accounts and shared accounts separately.
The results often surprise leadership.
Anyone who needs administrator rights should have two accounts: a regular one for email, browsing and daily work, and a separate admin account used only for administrative tasks. This way, a phishing click on the daily account does not hand over the keys. Protect admin accounts with multi-factor authentication, and ideally restrict where they can sign in.
Work through the list with a simple test: does this person need this level of access to do their job regularly?
Remove local administrator rights from standard users. If someone occasionally needs to install something, have IT do it or use a controlled approval process.
Reduce the number of top-level administrators to the minimum, often a handful, and make sure there are at least two so that emergency access is not dependent on one person.
Replace broad EMR roles with more specific ones, in consultation with clinical leadership and the vendor.
Disable accounts that are unused or whose owners cannot be identified.
Expect some pushback. Explain the reasoning in plain language, and provide a quick path for legitimate requests.
Give each vendor technician a named account, not a shared login
Enable vendor access only when needed and set expiration dates
Limit service accounts to the specific systems and permissions required
Store service account passwords in a secure vault and rotate them on a schedule, noting that some applications need careful coordination when passwords change
Logging and alerts for changes to administrator groups, new admin accounts and unusual sign-ins
Regular access reviews, perhaps quarterly for administrators and annually for other roles, in which managers confirm that each person's access is still appropriate
Approval workflows for granting elevated access
Time-limited elevation, where tools allow someone to receive admin rights for a short period rather than permanently
Break-glass accounts for emergencies, with long, unique passwords stored securely and monitored for any use
Clinical workflows depend on reliability. Introduce changes in stages, test them with a small group, and keep a fast channel for fixing access problems, especially on night shifts. If removing rights from a shared nurse station computer breaks a legitimate task, find the right fix, such as a specific permission or a managed software deployment, rather than restoring blanket rights.
Fewer people with administrator roles
Separate admin and daily accounts
No shared admin logins
Vendors with named, expiring accounts
Access reviews completed and documented
Alerts when privileges change
How many people could delete our backups, disable our security software or create new accounts tonight? If the answer is unclear, that is where to begin.
UnityCare IT helps healthcare organizations review privileged access, separate admin accounts and set up periodic access reviews, working carefully around clinical workflows. If you would like to know who has the keys today, we can help find out.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172