Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Healthcare PAM gaps: are your access controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19428
Topic starter  

TL;DR: Healthcare cyber risk remained acute in 2025, with breaches affecting more than 139 million patients and a 2025 Ponemon-Proofpoint survey finding 93% of US healthcare organisations had at least one cyberattack in the prior year, while privileged access abuse remained a leading root cause of data loss, Securden reports. The governance problem is not only compliance pressure, but unmanaged privileged accounts, third-party access, and standing credentials across clinical and device environments.

NHIMG editorial — based on content published by Securden: healthcare privileged access management, ePHI protection, and compliance controls

By the numbers:

Questions worth separating out

Q: What breaks when privileged access is not tightly controlled in hospitals?

A: When privileged access is not tightly controlled, attackers can alter systems, disable safeguards, or reach sensitive data faster than defenders can respond.

Q: Why do healthcare organisations need PAM for both compliance and patient safety?

A: Because the same privileged account can expose ePHI, change clinical configurations, and affect device availability.

Q: What do healthcare IAM programmes often get wrong about access reviews?

A: They often review whether an account should exist instead of whether the person still needs specific clinical entitlements.

Practitioner guidance

  • Inventory privileged paths across clinical and device systems Map every admin route into EHRs, imaging platforms, infusion pumps, patient monitors, cloud consoles, and support portals so you know where elevated access can change patient-impacting systems.
  • Remove standing access from contractor and vendor accounts Assign time-limited access for biomedical suppliers, IT contractors, and support teams, and require explicit renewal before access can continue beyond the active work order.
  • Record and review privileged sessions by actor type Use session recording, command logging, and account attribution for humans, service accounts, and vendor sessions so audit trails show who accessed what and when.

What's in the full article

Securden's full article covers the operational detail this post intentionally leaves for the source:

  • Health-sector-specific PAM workflows for providers, insurers, and manufacturers that need different access models
  • Detailed examples of vaulting, session recording, and endpoint privilege management in clinical environments
  • Compliance mapping for HIPAA, HITECH, HITRUST, ISO 27001, and cyberinsurance reporting
  • Vendor-managed access and credential rotation patterns for third-party support teams

👉 Read Securden's analysis of PAM, HIPAA, and privileged access risk in healthcare →

Healthcare PAM gaps: are your access controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 19019
 

Privileged access is the highest-leverage control in healthcare because it sits above both data and device safety. A healthcare breach is rarely just a confidentiality failure. Once elevated access reaches EHRs, imaging systems, or connected devices, the same identity path can affect records, availability, and clinical workflow. Practitioners should treat privileged access as a safety boundary, not only an IT permission model.

A few things that frame the scale:

  • The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Our research also found that 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which shows the scale of the governance gap.

A question worth separating out:

Q: Who is accountable for third-party access when a vendor relationship ends?

A: Accountability should sit with the business owner of the relationship, but IAM, PAM, and security teams must own the technical revocation and validation steps. If no one is responsible for proving access removal, the organisation has governance in name only.

👉 Read our full editorial: Healthcare privileged access failures expose ePHI and device risk



   
ReplyQuote
Share: