Year-End Review: Auditing User Access Before January

Every organization accumulates access it no longer needs. An employee changes roles but keeps old permissions. A traveling nurse finishes a contract, but the account stays active. A vendor technician has remote access from a project two years ago. Each leftover account is a quiet risk, because attackers like unused accounts that nobody is watching. The end of the year is a good time to clean up.

Why access reviews matter

The HIPAA Security Rule includes standards for information access management, workforce security and access control. These expect you to authorize access appropriately, to terminate it when employment ends and to review activity. The minimum necessary principle suggests that people should have only the access they need for their jobs.

A periodic review also helps in practical ways:

It reduces the number of accounts an attacker could misuse.

It catches terminated employees whose accounts were missed.

It reveals shared or generic accounts that weaken accountability.

It provides documentation for audits and insurance applications.

What to review

Start with the systems that hold the most sensitive information or the most power:

Domain or network accounts

Email and cloud accounts

EHR and eMAR, including role assignments

Billing, payroll and HR systems

Remote access, VPN and remote desktop accounts

Administrator accounts on servers, firewalls and cloud consoles

Vendor and contractor accounts

Shared mailboxes and generic logins

Wi-Fi credentials and badge access

A step-by-step process

1. Export a list of accounts

IT pulls a list of users from each system with their last sign-in dates, roles and status.

2. Compare it to the current staff roster

Ask HR for an up-to-date list of active employees, agency staff and contractors. Flag any accounts that do not match a current person.

3. Look for inactivity

Accounts with no sign-ins for 60 or 90 days deserve attention. Some are legitimate, such as an employee on leave, but they should be confirmed and possibly disabled.

4. Ask managers to confirm access

Send each department head a list of their team members and the access each person has. Ask them to confirm that it is still appropriate, or to request changes. Keep their responses as evidence.

5. Review privileged accounts closely

Administrator accounts should be few, named and protected with multifactor authentication. Remove administrator rights from anyone who does not need them. Check for old service accounts and generic admin logins.

6. Check third-party access

List vendors and contractors who have accounts or remote access. Confirm that each still has a current contract and a business associate agreement where PHI is involved. Disable access that is no longer required.

7. Fix and document

Disable or delete unnecessary accounts, adjust permissions and record what you changed, who approved it and when. Disabling an account first, then deleting after a waiting period, gives you a safety net if someone discovers a dependency.

Common findings

Former employees with active accounts

Staff who moved departments and retained old access

Shared accounts used by multiple people

Administrator accounts used for daily work

Test accounts and service accounts with weak passwords

Agency staff accounts left active after contracts ended

Make it routine

An annual review is a minimum. Many organizations review privileged access quarterly and tie offboarding to a checklist so accounts are disabled on the last day. Add it to your calendar, and assign an owner.

Connect it to HR

The most reliable fix for lingering accounts is a link between HR events and IT actions. When a hire, transfer or termination occurs, an automatic ticket should notify IT. Agree on timing, such as same-day disabling for involuntary terminations.

Getting help

UnityCare IT performs access reviews for healthcare organizations and helps build onboarding and offboarding processes. If you would like help finding stale accounts before the new year, we can run the review with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172