Skip to main content
← All case studies

Healthcare

Closing the password-only front door at a community hospital

Community hospital · one site plus four clinics · 4-person IT team, no dedicated security staff

100%

MFA coverage on remote access

18

vendor accounts scoped to their BAA and given expiry dates

0

patient-data findings at the next audit

15 min

break-glass activation, fully logged

This is an illustrative engagement, composed from incident and enforcement patterns published since 2024. It is not an account of a specific client, and the figures are representative of the pattern rather than drawn from one organisation's records. How we build these →

Context

The pattern behind the sector’s most damaging intrusions of the last two years is unglamorous: one stolen password, one remote-access portal that accepted it on its own, and nothing standing between the two.

The hospital knew this. It was in no way negligent. It had four people running every system in the building, and multi-factor authentication had sat on the list behind an EHR upgrade, a phone system migration and two staff departures. This is the ordinary situation at a small provider, and it is why the fix has to fit into the hours that actually exist.

Regulatory driver

HIPAA Section 164.312(a)(1) and (d) — access control and person-or-entity authentication — read against the OCR audit protocol, where the evidence sampled is how quickly access ends when someone leaves, whether emergency access is tested, and the audit controls under Section 164.312(b). Vendor access sits inside the BAA obligation, not outside it. The proposed Security Rule update would move multi-factor authentication from addressable to required; it is not final, so the work was scoped to what is in force today and built so that finalization changes nothing.

What we did

Remote access first, everything else later. Entra ID Conditional Access with phishing-resistant multi-factor authentication went in front of the Citrix portal before anything else was touched. Old authentication protocols that bypass it were switched off rather than monitored. This was the single change that answered the board’s question, and it went first for that reason.

Vendor accounts got boundaries. Eighteen third-party accounts held permanent access to the EHR well beyond what their contracts covered — the usual accumulation of software vendors, billing services and imaging partners. Each was checked against its BAA, cut back to what it actually needed, and given an expiry date. Vendors now re-confirm annually or the access lapses on its own.

Emergency access that actually works. Clinicians must be able to reach records in a crisis, and HIPAA requires the procedure to exist. It was rebuilt to expire on its own, raise an alert when used, and log everything — then tested with the clinical staff before it counted. Nobody gets locked out of a patient record because of a control we put in.

Result

Next audit: no patient-data findings. The answer to the board’s question is now no, and it can be shown rather than asserted, because the evidence is produced as the systems run instead of assembled afterwards.

Scope note: this was one workstream over six weeks, covering remote access, vendor accounts and emergency access. The four-person IT team runs it now; we wrote the runbook and left.

Stack hardened: CitrixMicrosoft Entra IDEpic-adjacent EHRMicrosoft Purview

Recognise any of this in your own setup?

Composites are built from patterns, and patterns repeat. In 30 minutes we can tell you how much of this one applies to you, and which part of it would surface first under examination.

Book an Identity Risk Review