Shadow IT: Finding Apps Staff Signed Up for on Their Own

A nurse manager wants to share a schedule with her team, so she signs up for a free scheduling app. A business office employee needs to send a large file, so he uses a file-sharing site. A therapist records dictation with a personal phone app. None of these people are trying to cause trouble. They are trying to get work done. But each of those tools may now hold protected health information outside of your control, with no business associate agreement, no security review and no way for you to shut off access when someone leaves.

This is shadow IT: technology used for work without the knowledge or approval of the people responsible for security. It is common in every industry, and healthcare is no exception. The goal is not to punish staff. It is to find these tools, understand why they were adopted and bring them into a safe arrangement.

Why shadow IT is a risk

Data leaves your control. Information stored in an unapproved app is not covered by your security settings, backups or retention rules.

No agreement is in place. If a vendor handles protected health information for you, HIPAA generally expects a business associate agreement. Free consumer tools rarely offer one.

Accounts outlive employees. If staff sign up with personal email addresses, you cannot turn off access when they leave.

Weak sign-in protection. Passwords may be reused, and multi-factor authentication may be off.

Blind spots in an incident. If something goes wrong, you may not even know which tools held your data.

Start with a non-punitive tone

The most important step comes before any technical work. Tell staff what you are doing and why. Explain that the goal is to protect residents and employees, and that people will not be disciplined for disclosing tools they have been using in good faith. If staff fear getting in trouble, they will hide the tools, and you will learn less.

Invite people to tell you what they use and what problem it solves. Those answers are more valuable than any scan, because they reveal unmet needs.

Discovery techniques

Use several methods together, since none is complete.

Ask people

A short, friendly survey or conversation at team meetings is surprisingly effective. Ask: "What apps or websites do you use for work that IT did not set up for you?" Make it easy and anonymous if needed.

Review your cloud and identity logs

If you use Microsoft 365 or Google Workspace, review which third-party applications have been granted access to company accounts. Look for apps that employees authorized with their work sign-in, and check what permissions they have. Your administrator can usually list these and remove ones that are unnecessary.

Check network and DNS logs

Your firewall or DNS filtering service may report which web services are being used. Reports often group sites by category, such as file sharing, messaging or note-taking, which makes unfamiliar tools stand out.

Look at expenses

Corporate card statements and expense reports can reveal subscriptions that departments paid for themselves.

Review browser extensions and installed software

Managed devices can be checked for installed applications and browser extensions. Unapproved extensions can read data on the pages people visit, so they deserve attention.

Build a simple review process

Once you have a list, review each tool rather than banning everything. For each one, ask:

What is it used for, and by whom?

What kind of data goes into it? Does it include protected health information?

Does the vendor offer a business associate agreement, encryption and multi-factor authentication?

Can accounts be managed centrally?

Is there an approved tool that already does the same job?

Then decide one of three outcomes: approve it and set it up properly, replace it with an approved alternative, or retire it, with help moving the data out.

Offer a better path

Shadow IT often grows because the official process is slow. Publish a simple way to request new tools, with a quick answer. Keep an approved list of applications that staff can see, so they know what is available. When someone has a real need, such as sharing schedules or secure messaging, provide a safe option instead of just saying no.

Put guardrails in place

Restrict which third-party apps users can authorize in your cloud accounts, or require administrator approval.

Use device management to control software installation where appropriate.

Include a short section in your acceptable use policy and security training about using unapproved tools with resident information.

Make sure offboarding includes a check for accounts and tools tied to the departing employee.

How UnityCare IT can help

UnityCare IT helps healthcare and senior-living organizations find unsanctioned tools, review them fairly and set up approved alternatives that staff will actually use. If you suspect there is more running in your organization than you know about, we can help you find out.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172