Clinical workflow vs least privilege
Shared logins at nursing stations "because care can't wait" break accountability chains — the exact pattern examiners probe.
Industry · Healthcare & HealthTech
Healthcare has recorded the highest average breach cost of any industry in every edition of IBM's Cost of a Data Breach report for over a decade — USD 6.64M in the 2026 edition. And the enforcement pattern has shifted from breach response to whether you did the risk analysis at all.
Your Regulatory Reality
HIPAA Security Rule
Section 164.308(a)(4) information access management; Section 164.312(a)(1)/(d) access control and authentication. These are the standards in force today.
The proposed Security Rule update
The NPRM published 6 January 2025 would make MFA and encryption mandatory rather than "addressable." It is still not finalized: comments closed 7 March 2025, OMB currently targets July 2027, and more than 100 hospital systems and provider associations have asked HHS to withdraw it. Plan for it; do not budget as though it were law.
OCR Risk Analysis Initiative
Between January and August 2025 OCR announced 16 resolution agreements centred on failure to conduct an accurate and thorough risk analysis. This — not a headline breach — is the live enforcement pattern for the average covered entity and business associate.
HITRUST CSF
Certification your enterprise and payer customers increasingly demand — identity controls form its largest domain.
OCR audit protocol
Access reviews, termination evidence, emergency-access testing, and audit controls under Section 164.312(b).
PHIPA (Ontario)
Health-sector equivalents of HIPAA access controls. A US vendor is usually an agent of a health information custodian rather than a business associate, and lockbox and consent-directive handling is an authorization problem, not a policy one.
PIPEDA / Law 25
Consent and safeguard expectations for commercially handled health data, shaping consent architecture and data-subject request design directly.
Provincial EHR agreements
Identity obligations flow down contractually to every vendor touching provincial systems.
Where It Breaks
Shared logins at nursing stations "because care can't wait" break accountability chains — the exact pattern examiners probe.
Dozens of third parties hold standing EHR integrations far beyond contract scope, with no expiry or re-attestation.
LLM pipelines wired in via unowned service accounts — powerful models, real patient data, zero oversight.
Emergency clinical procedures untested since implementation: no alarms, no expiry, no logs.
How We Fix It
An Identity Risk Review maps your current gaps against exactly what OCR examiners test for — with a prioritized fix list.
Book an Identity Risk Review