Applied IAM

Identity Security for Healthcare

Healthcare has carried the highest average breach cost of any industry for thirteen consecutive years. IBM's 2026 Cost of a Data Breach report puts it at $6.64 million, down from the previous year but still ahead of every other sector. The reason is not indifference. Clinical environments are built around speed of access, and identity controls that slow a clinician down get worked around by the end of the week.

HIPAA Security RuleEHR and PACSMedical devicesBreak-glassOCR evidence
Access recordEmergency access · break-glass
EHR and PACS
WhoOn-call clinicianWhyEmergency careAccessInstant
  1. 02:14
    Instant accessIn an emergency a clinician needs access immediately
    Granted
  2. 02:14–02:51
    Full logging
    • 02:14Chart opened in the EHR
    • 02:17Imaging viewed in PACS
    • 02:26Medication record updated
    • 02:51Session closed and recorded
    Logged
  3. Next day
    A review afterwardsEvery emergency access reviewed
    Reviewed

Break-glass is a clinical requirement, not an exception.

The clinical constraint

Why clinical environments break identity controls

Three things are true in hospitals and almost nowhere else.

  • Shift work and shared logins. Staff rotate through shifts and share workstation logins because signing in individually costs seconds at the bedside. The result is an audit trail that cannot attribute an action to a person, which is exactly what an OCR review asks for.
  • Break-glass is a clinical requirement, not an exception. In an emergency a clinician needs access immediately. Any control that cannot accommodate that gets bypassed, so the control has to be designed around it rather than in spite of it: instant access, full logging, and a review afterwards.
  • Medical devices cannot be patched or joined. Infusion pumps, imaging systems and patient monitors run software that rarely receives security updates and often cannot take an agent or join a directory. Access control has to happen around them, at the network and the credential rather than on the device.

Insider misuse of legitimate access is a recurring pattern in healthcare breaches, which is why detection matters as much as prevention here, and why session recording is worth more in a hospital than almost anywhere.

The framework

What the HIPAA Security Rule asks of access control

45 CFR 164.308 requires access controls, audit logs and a risk analysis. Not as best practice — as a legal requirement, with civil penalties that can reach $2.19 million a year for repeated violations of the same requirement. The 2026 Security Rule update adds a technology asset inventory requirement, which is where the medical device problem stops being optional, and the HITECH Act raises breach penalties on top.

The HIPAA Security Officer, usually the CISO, is legally responsible for access controls and technical safeguards. In larger health systems the Chief Privacy Officer signs alongside them. Practically, the review asks four things: who can reach ePHI, whether it is least privilege, whether it is logged, and whether you can produce the evidence. Where the answer to the last one is no, that is the work. Start with a compliance readiness assessment, and where the systems warrant it, HIPAA penetration testing evidences the risk analysis.

The estate

Where access breaks down across a hospital

  • Clinical systems and ePHI

    EHR and PACS access that follows the person rather than the workstation, with break-glass built in and every emergency access reviewed.

  • Medical devices and IoMT

    Segmented, with privileged access to device management consoles brokered and recorded, because the device itself cannot defend itself.

  • Vendor and third-party access

    A vendor with standing access to patient data is a way in that your own defenses never see. Vendor sessions brokered, recorded, and expired at grant rather than discovered at audit.

  • Clinician, contractor, resident and locum lifecycle

    Populations that arrive and leave constantly, with access that has to be right on the first shift and gone on the last. That is IGA implementation work.

Hospital · planSegmentedWay in from outside
1Clinical systems and ePHI
EHRPACS
Break-glass built inAccess follows the person, not the workstation
2Medical devices and IoMT
Segmented
Infusion pumpsImaging systemsPatient monitors
Device management consoles brokered and recorded
3Vendor and third-party access
BrokeredRecordedExpired at grant
Not discovered at audit
4Clinician, contractor, resident and locum lifecycle
First shiftLast shift
Right on the first, gone on the last
Triggers

Where a program usually starts

An OCR finding or a failed risk assessment

The most common trigger. Map the finding to the control, fix the control.

A ransomware scare

Industry reporting puts hospital downtime cost as high as $900,000 a day. The path in is almost always a credential, and PAM implementation closes it.

A cyber-insurance renewal

Insurers now expect MFA on privileged access, brokered vendor sessions and security awareness training with records, before they will renew.

Where the privileged platform is CyberArk, CyberArk implementation is the delivery route, and service account management handles the credentials clinical systems use to talk to each other.

FAQs

What health systems ask first

By making access to ePHI attributable, least-privilege, logged and evidenced — the four things an OCR review actually checks. Controls produce the evidence themselves rather than someone reconstructing it.

Not if break-glass is designed in from the start. Emergency access is instant, fully logged and reviewed afterwards. The controls that fail in hospitals are the ones that made a clinician wait; the ones that hold are the ones that never did.

Yes, around the device rather than on it: network segmentation, brokered and recorded access to the management console, and vaulted credentials for the service accounts the device uses. The device stays untouched, which is usually a regulatory requirement anyway.

By making the individual login faster than the shared one — tap-and-go or badge access into a shared workstation, with the session attributed to the person rather than the machine. Shared logins persist because they are convenient. Remove the inconvenience and they stop.

The risk analysis, the access control policy, evidence that access to ePHI is reviewed, audit logs showing who accessed what, and — since the 2026 update — the technology asset inventory. All of it produced on request, not assembled in the week before.

See who can really reach your patient data

A free audit is a 30-minute review of your privileged and clinical access by a certified engineer, with the findings in writing. The Healthcare blind spot brief covers the largest healthcare breach ever recorded and the access gap behind it.