Walk through almost any busy care unit and you may find a sticky note with a password, a computer left logged in under someone else's name, or a generic login used by everyone on the shift. Nobody is trying to be careless. Staff are trying to document, pass medications and respond to residents, and a login screen feels like an obstacle. But shared credentials create real problems for privacy, accountability and security. The solution is not simply to scold staff. It is to make the secure path the easy path.
No accountability. If five people use the same account, an audit log cannot show who viewed or changed a resident record. The HIPAA Security Rule requires unique user identification and audit controls, and shared accounts undermine both.
Inappropriate access. A shared account usually carries the highest access anyone on the team needs, which means everyone gets more access than their role allows.
No way to revoke. When someone leaves, the password does not change, or it changes and nobody knows.
Investigation dead ends. If a record is altered or a breach is suspected, you cannot determine who was responsible.
Insurance and survey exposure. Insurers and surveyors increasingly expect unique accounts and multi-factor authentication.
Understanding the cause helps fix it. Common reasons include:
Computers that take a long time to log in, so staff avoid logging out.
Complicated passwords that are hard to type on a cart during a busy med pass.
Short windows of time with high demand, such as shift change or mealtimes.
Agency or float staff who have not yet received accounts.
Legacy devices or software that do not support individual logins.
A culture where sharing was never challenged.
Ask staff directly what slows them down. The answers often point to technical fixes.
Badge tap or proximity cards allow staff to sign in and out of shared workstations in seconds.
Fast user switching and single sign-on reduce the number of passwords people have to type.
Session roaming, where a user's desktop follows them from computer to computer, can shorten login time on shared workstations.
Hardware and image tuning, because slow, outdated computers are often the real cause of the shortcut.
Automatic screen lock after a short period of inactivity, with a quick way to unlock, protects records without relying on memory. On shared workstations, shorter timeouts are appropriate. Where staff fear losing their work, check that applications save progress so a lock does not mean starting over.
Long passphrases that people can remember are easier than short, complex strings that must be written down. A business-grade password manager can handle shared system credentials, such as a vendor portal, without anyone passing them around by text.
Float, agency and per diem staff need named accounts too. Build an onboarding process that creates them before the first shift and expires them automatically. See your offboarding procedure for the other end.
If a medical device or an old application genuinely supports only a shared login, document it as a risk. Restrict where it can be reached on the network, limit what it can access, log use through a sign-out sheet or other compensating control, and plan its replacement.
Write a short policy: each person uses only their own login, logs out or locks the screen when they step away, and never asks another person for a password. Explain the why in training, using plain language about resident privacy and the staff member's own protection, since an action taken under your name is attributed to you.
Supervisors play a major role. If leaders routinely log in for others or tolerate shared logins during busy times, the policy will not hold. Spot-check units occasionally, and treat repeat violations consistently without making the discussion punitive.
Review access logs periodically for unusual patterns, such as logins at odd hours, many logins from one device, or access to records of residents outside someone's unit. Your EMR vendor and IT provider can help set up reports.
Start with one unit as a pilot, collect feedback, and adjust before rolling out broadly. UnityCare IT helps care facilities choose badge-based login, tune workstations and set up accounts so staff can do the right thing without losing time. If shared logins are common in your building, we can help you take them out one step at a time.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172