Every organization accumulates access it no longer needs. An employee changes roles but keeps old permissions. A traveling nurse finishes a contract, but the account stays active. A vendor technician has remote access from a project two years ago. Each leftover account is a quiet risk, because attackers like unused accounts that nobody is watching. The end of the year is a good time to clean up.
The HIPAA Security Rule includes standards for information access management, workforce security and access control. These expect you to authorize access appropriately, to terminate it when employment ends and to review activity. The minimum necessary principle suggests that people should have only the access they need for their jobs.
A periodic review also helps in practical ways:
It reduces the number of accounts an attacker could misuse.
It catches terminated employees whose accounts were missed.
It reveals shared or generic accounts that weaken accountability.
It provides documentation for audits and insurance applications.
Start with the systems that hold the most sensitive information or the most power:
Domain or network accounts
Email and cloud accounts
EHR and eMAR, including role assignments
Billing, payroll and HR systems
Remote access, VPN and remote desktop accounts
Administrator accounts on servers, firewalls and cloud consoles
Vendor and contractor accounts
Shared mailboxes and generic logins
Wi-Fi credentials and badge access
IT pulls a list of users from each system with their last sign-in dates, roles and status.
Ask HR for an up-to-date list of active employees, agency staff and contractors. Flag any accounts that do not match a current person.
Accounts with no sign-ins for 60 or 90 days deserve attention. Some are legitimate, such as an employee on leave, but they should be confirmed and possibly disabled.
Send each department head a list of their team members and the access each person has. Ask them to confirm that it is still appropriate, or to request changes. Keep their responses as evidence.
Administrator accounts should be few, named and protected with multifactor authentication. Remove administrator rights from anyone who does not need them. Check for old service accounts and generic admin logins.
List vendors and contractors who have accounts or remote access. Confirm that each still has a current contract and a business associate agreement where PHI is involved. Disable access that is no longer required.
Disable or delete unnecessary accounts, adjust permissions and record what you changed, who approved it and when. Disabling an account first, then deleting after a waiting period, gives you a safety net if someone discovers a dependency.
Former employees with active accounts
Staff who moved departments and retained old access
Shared accounts used by multiple people
Administrator accounts used for daily work
Test accounts and service accounts with weak passwords
Agency staff accounts left active after contracts ended
An annual review is a minimum. Many organizations review privileged access quarterly and tie offboarding to a checklist so accounts are disabled on the last day. Add it to your calendar, and assign an owner.
The most reliable fix for lingering accounts is a link between HR events and IT actions. When a hire, transfer or termination occurs, an automatic ticket should notify IT. Agree on timing, such as same-day disabling for involuntary terminations.
UnityCare IT performs access reviews for healthcare organizations and helps build onboarding and offboarding processes. If you would like help finding stale accounts before the new year, we can run the review with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172