Access state becomes inconsistent across systems, so a terminated employee, contractor, or visitor can still retain one valid path into the organisation after another path is removed. That creates revocation delay, weak accountability, and incomplete audit evidence. In healthcare, the problem is not just inefficiency, but the inability to prove that access is current everywhere it matters.
Why Separate Badge and IT Access Breaks Revocation
When physical badge status and digital access status are administered by different teams, the organisation loses a single authoritative view of who should still be trusted. Deactivation in one system does not guarantee deactivation in the other, so the control failure is not just duplication, but a split revocation path that can leave a former worker, contractor, or visitor with residual access.
That split matters most at termination and role change events, where delay is common and the risk is highest. In practice, the question is whether access is being removed from the person, or only from one system that represents the person. If those states diverge, the organisation can no longer state with confidence that access has been fully withdrawn.
Why This Creates Audit and Accountability Gaps
Separate badge and IT administration also weakens auditability because evidence becomes fragmented across facilities, HR, security, and IT. A reviewer may see that one control fired, but not that all effective access paths were removed, which makes recertification and post-incident review harder.
This is especially problematic in healthcare because access decisions often span clinical areas, back-office systems, shared workspaces, and visitor-controlled zones. If the logs do not line up, the organisation may be unable to prove current access state for a given individual at a specific point in time. That is an accountability problem, not only an administrative one, and it erodes confidence in the control environment.
Why It Becomes a Practical Security Exposure in Healthcare
When badge and IT access are decoupled, the remaining access path becomes an attractive foothold for misuse, whether accidental or malicious. A user whose digital account is removed but whose badge still works can still enter restricted areas, while a disabled badge paired with valid IT credentials can still expose records, terminals, or shared systems.
Healthcare environments magnify the issue because many workflows are time-sensitive and rely on mixed physical and logical access. The security problem is therefore the residual privilege window, where one control has been updated and the other has not. That window is long enough to create exposure even if the original removal request was correct.
Risk and Threat Considerations
Separated badge and IT administration creates a revocation gap that adversaries, insiders, and even careless operational processes can exploit. The main risk is stale access surviving after employment or engagement ends, which can enable unauthorised entry, unauthorised system use, or both.
Failure mechanism: Access is removed in one system but not the other, so the organisation retains an inconsistent trust state and cannot reliably enforce least privilege or complete offboarding.
Impact: A former or suspended user can retain a valid path into facilities or systems, increasing exposure to data access, sabotage, fraud, or delayed incident detection.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Unified account lifecycle control is central to removing access across badge and IT systems. |
| IA-5 — Authenticator Management | Badge and IT access both depend on managed authenticators and timely revocation. | |
| Recommendation — Synchronise account disablement and removal actions across all access systems. Track and revoke authenticators as part of the same offboarding event. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | This problem is fundamentally about inconsistent access control across systems. |
| Recommendation — Align physical and logical access rules to one authoritative status source. | ||
| CIS Controls v8 | CIS-5 — Account Management | CIS account management directly addresses coordinated removal of access on exit. |
| Recommendation — Centralise account and access removal so termination events update every system. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | The issue is inconsistent identity and access state across linked control planes. |
| Recommendation — Maintain a single authoritative access state across identity and physical access systems. | ||
Practitioner Guidance
What to verify: Confirm that termination, suspension, contractor end dates, and visitor expiry events trigger all relevant revocation paths, not just the directory account or just the badge. The test is whether you can prove, from one case record, that every active access path was removed within the required time window.
What good looks like: The badge system, IT identity system, and HR or access approval source all reconcile to the same authoritative status, with exceptions visible and time bound. Where healthcare operations require temporary exceptions, those exceptions should be explicit, approved, and easy to audit.
Common mistake: Treating physical access and digital access as separate operational problems. They are different controls, but they protect the same trust decision, so any separation that prevents shared status and shared revocation creates avoidable exposure.
Practitioner takeaway: If you cannot answer, for any person, “what access remains right now?” across both badge and IT systems, then revocation is not actually complete.
Related resources from NHI Mgmt Group
- What breaks when privileged access and device trust are managed separately?
- What breaks when access and device controls are managed in separate systems?
- What breaks when access control is managed separately by country or office?
- What breaks when access reviews are managed manually across ERP systems?