Join our Newsletter — 33% off our NHI Course

What do healthcare organizations get wrong about separation of duties across applications?

A common mistake is treating separation of duties as a single-application problem. In practice, risky combinations often appear across multiple systems, especially in billing and revenue workflows, where entitlements can overlap invisibly. Teams also miss third-party access, which should be included in the same governance review to prevent toxic access combinations from bypassing internal controls.

Why separation of duties breaks down when you only review one application at a time

In healthcare, separation of duties is usually discussed as if each application can be assessed in isolation. That misses the real control problem: users often accumulate entitlements across patient billing, claims, revenue cycle, ERP, and support tools that become risky only when combined. The control objective is not just single-role restriction, it is preventing cross-system access patterns that let one person complete a sensitive process end to end.

That is why the review scope has to follow the business workflow, not the application boundary. A user may look appropriately limited in each system and still be able to create, approve, correct, and release records across the whole process. In practice, separation of duties is a cross-application authorization question, and it only works when entitlement analysis is done against the full path a user can take through the workflow.

Healthcare teams also under-estimate how often the dangerous combination is split across internal and external systems. Billing exceptions, claims adjustments, refunds, vendor support actions, and master-data changes may each appear harmless on their own, but together they can create a toxic access path. Reviewers need to identify the business outcome being protected, then test whether any one person or third party can reach that outcome without an independent checkpoint.

Why third-party access and legacy workflow exceptions matter as much as internal roles

Third-party support access is often excluded from SoD reviews because it is treated as temporary, exceptional, or outside the core identity governance process. That is a mistake. External vendors, managed service providers, implementation partners, and clearinghouse access can participate in the same high-risk workflow as employees, especially when they can view, edit, or release records in systems that feed finance or revenue operations. NHIMG’s Ultimate Guide to Non-Human Identities notes that 92% of organisations expose NHIs to third parties, which is a useful reminder that external access is a governance issue, not just a vendor management issue.

The practical failure mode is usually incomplete inventory. Teams review named application roles, but they do not map entitlements that are inherited through integrations, shared admin functions, service access, or privileged support channels. That creates hidden overlap, especially when access is granted to solve an operational problem and then left in place after the need has passed.

Where healthcare environments still rely on older platforms, the risk is even higher because role design may not reflect current business process boundaries. If an application cannot express granular separation cleanly, the compensating control has to move up a layer, into workflow approval, monitoring, and periodic access recertification across the whole process chain.

Risk and Threat Considerations

The main risk is not that one control is missing inside a single system, it is that a user can assemble a complete fraud, data manipulation, or release path by combining ordinary access across several systems. That weakens accountability, increases insider-risk exposure, and can allow billing, claims, and records workflows to be altered without an independent check.

Failure mechanism: entitlement reviews are performed per application instead of per business process, so overlapping permissions remain invisible when they are split across systems or shared with third-party support.

Impact: an attacker or insider can exploit the combined access path to approve, modify, or release transactions, create improper payments, mask errors, or move laterally through healthcare operations without triggering a single-system control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management Cross-application SoD depends on reviewing and limiting user access paths.
Recommendation — Review and remove conflicting access across systems that enable one person to complete a controlled workflow.
NIST CSF 2.0 PR.AC — Access Control Management SoD is a cross-system access control issue affecting authorization boundaries.
GV.RM — Risk Management Strategy Healthcare SoD needs governance of toxic combinations across business processes.
Recommendation — Enforce authorization boundaries across applications so no single user can execute incompatible workflow steps. Define SoD risk thresholds at the process level rather than the individual application level.
OWASP Non-Human Identity Top 10 NHI-03 — Overprivileged Non-Human Identities Third-party support and service access can create hidden toxic combinations in shared workflows.
NHI-10 — Third-Party NHI Risk External access is a material part of SoD governance when vendors participate in production workflows.
Recommendation — Audit third-party and service access for overlapping permissions that bypass internal SoD controls. Include vendor and support accounts in the same SoD review as employee accounts.
NIST SP 800-63 IAL — Identity Proofing and Enrollment Where third parties or privileged users are onboarded, strong identity assurance supports trustworthy access governance.
Recommendation — Require strong identity assurance before granting workflow access that could create toxic combinations.

Practitioner Guidance

What to verify: Build the review around the workflow, not the application list. The question is whether one person can complete a sensitive outcome without an independent approver, reviewer, or reconciler somewhere in the chain.

Common mistake: Treating third-party support as an exception rather than part of the same SoD model. If vendors can intervene in production workflows, their access has to be included in the same toxic-combination review as employee access.

What good looks like: Access recertification identifies overlapping entitlements across systems, shows who can initiate and who can complete each step, and flags any path where the same actor can both create and approve a controlled business event.

Practitioner takeaway: In healthcare, separation of duties fails most often when governance stops at the application boundary, so the control should be measured against end-to-end business authority, not isolated role names.