An OCR finding or a failed risk assessment
The most common trigger. Map the finding to the control, fix the control.
Healthcare has carried the highest average breach cost of any industry for thirteen consecutive years. IBM's 2026 Cost of a Data Breach report puts it at $6.64 million, down from the previous year but still ahead of every other sector. The reason is not indifference. Clinical environments are built around speed of access, and identity controls that slow a clinician down get worked around by the end of the week.
02:14Chart opened in the EHR02:17Imaging viewed in PACS02:26Medication record updated02:51Session closed and recordedBreak-glass is a clinical requirement, not an exception.
Three things are true in hospitals and almost nowhere else.
Insider misuse of legitimate access is a recurring pattern in healthcare breaches, which is why detection matters as much as prevention here, and why session recording is worth more in a hospital than almost anywhere.
45 CFR 164.308 requires access controls, audit logs and a risk analysis. Not as best practice — as a legal requirement, with civil penalties that can reach $2.19 million a year for repeated violations of the same requirement. The 2026 Security Rule update adds a technology asset inventory requirement, which is where the medical device problem stops being optional, and the HITECH Act raises breach penalties on top.
The HIPAA Security Officer, usually the CISO, is legally responsible for access controls and technical safeguards. In larger health systems the Chief Privacy Officer signs alongside them. Practically, the review asks four things: who can reach ePHI, whether it is least privilege, whether it is logged, and whether you can produce the evidence. Where the answer to the last one is no, that is the work. Start with a compliance readiness assessment, and where the systems warrant it, HIPAA penetration testing evidences the risk analysis.
EHR and PACS access that follows the person rather than the workstation, with break-glass built in and every emergency access reviewed.
Segmented, with privileged access to device management consoles brokered and recorded, because the device itself cannot defend itself.
A vendor with standing access to patient data is a way in that your own defenses never see. Vendor sessions brokered, recorded, and expired at grant rather than discovered at audit.
Populations that arrive and leave constantly, with access that has to be right on the first shift and gone on the last. That is IGA implementation work.
The most common trigger. Map the finding to the control, fix the control.
Industry reporting puts hospital downtime cost as high as $900,000 a day. The path in is almost always a credential, and PAM implementation closes it.
Insurers now expect MFA on privileged access, brokered vendor sessions and security awareness training with records, before they will renew.
Where the privileged platform is CyberArk, CyberArk implementation is the delivery route, and service account management handles the credentials clinical systems use to talk to each other.
By making access to ePHI attributable, least-privilege, logged and evidenced — the four things an OCR review actually checks. Controls produce the evidence themselves rather than someone reconstructing it.
Not if break-glass is designed in from the start. Emergency access is instant, fully logged and reviewed afterwards. The controls that fail in hospitals are the ones that made a clinician wait; the ones that hold are the ones that never did.
Yes, around the device rather than on it: network segmentation, brokered and recorded access to the management console, and vaulted credentials for the service accounts the device uses. The device stays untouched, which is usually a regulatory requirement anyway.
By making the individual login faster than the shared one — tap-and-go or badge access into a shared workstation, with the session attributed to the person rather than the machine. Shared logins persist because they are convenient. Remove the inconvenience and they stop.
The risk analysis, the access control policy, evidence that access to ePHI is reviewed, audit logs showing who accessed what, and — since the 2026 update — the technology asset inventory. All of it produced on request, not assembled in the week before.

You deployed SSO. You turned on MFA. Then the auditor asked 'who has access to what, and should they?' — and that question lives in the gap between IAM and IGA.
Jul 24, 2026
The two pages that rank highest for this question are written by SailPoint and by Saviynt. Here is the version from people who deploy identity governance for a living.
Aug 31, 2026
Owning PAM and IGA is not the same as knowing your identity risk. What identity security posture management actually measures.
Jul 27, 2026A free audit is a 30-minute review of your privileged and clinical access by a certified engineer, with the findings in writing. The Healthcare blind spot brief covers the largest healthcare breach ever recorded and the access gap behind it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.