The failure is not only technical. If a hospital cannot show who opened a record, why MFA was or was not used, or how privileged and emergency access were governed, supervisors can treat the control environment as unproven. That creates an evidence gap that weakens compliance, accountability and incident reconstruction at the same time.
When the Control Cannot Be Shown, the Control Is Effectively Not There
Under NIS2, the practical problem is not just whether controls exist, but whether the hospital can demonstrate they are consistently enforced. A supervisor that cannot see evidence of access decisions, MFA outcomes, privileged access handling, or emergency access governance may conclude the control environment is unproven. That shifts the issue from configuration to assurance.
In a hospital, that distinction matters because access is tied to patient records, clinical continuity and accountability for who did what, when. If logging, approval records or review evidence are missing, the organisation may still believe controls are working, but it cannot prove that the intended access model is operating in real conditions.
The evidence question is therefore part of the control itself. When access control depends on exceptions, break-glass use, or privileged workflows, the control only holds if those exceptions are traceable and reviewable. Without that, the hospital has a policy statement, not an operationally defensible control.
What Fails in Practice: Assurance, Reconstruction and Governance
The first failure is assurance. If access governance cannot be demonstrated, auditors and regulators may treat the environment as incomplete even when no obvious incident has occurred. That can force remediation based on lack of proof alone, because the organisation cannot show that the right people had the right access for the right reason at the right time.
The second failure is reconstruction. After a suspected misuse of a record or a clinical access anomaly, the hospital needs to reconstruct the access path, the approval path and any MFA or emergency-access bypass. If those records are fragmented or absent, investigation becomes speculative and accountability weakens.
The third failure is governance. Weak proof often reveals deeper issues such as stale privileged access, unclear ownership of break-glass accounts, inconsistent recertification, or reliance on manual exceptions. In that situation, the control gap is not isolated to logging, it reaches the identity and access model itself, including how identity controls map to NIS2 obligations.
Why Hospitals Feel the Consequence More Sharply
Hospitals combine high-volume access, urgent exceptions and shared operational responsibility. That creates a difficult proof burden: clinicians need rapid access, security teams need control evidence, and supervisors need confidence that both are true at the same time. If those three needs are not aligned, the organisation can look compliant on paper while remaining unverifiable in practice.
Emergency access is the most common pressure point. Break-glass use is often legitimate, but it is also the easiest place for evidence to fail because urgency reduces pre-approval and post-event review discipline. The same issue appears with privileged access, especially when administrative access is shared, time-limited access is not enforced, or reviewers cannot tell whether access was assigned, activated or merely available.
For that reason, access models and governance discipline matter as much as technical enforcement. A hospital that needs a clearer operating model for roles, entitlements and privileged workflows should anchor it in authorisation models and privileged access management, because the proof problem usually starts where access becomes exception-driven.
Risk and Threat Considerations
When access controls cannot be evidenced, the risk is broader than non-compliance. The same gap can hide unauthorized record access, weaken detection of insider misuse and delay incident scoping because investigators cannot tell whether a given access event was legitimate or exceptional.
Failure mechanism: Missing or incomplete access records break the chain between policy, approval, actual use and post-event review, so control effectiveness cannot be demonstrated and suspicious access blends into normal activity.
Impact: Supervisors may treat the control environment as unproven, which can trigger remediation pressure, weaken incident reconstruction and leave the organisation unable to defend why sensitive patient data was accessed.
Practitioner Guidance
What to measure: Track the percentage of privileged and emergency access events that are fully attributable end to end, not just logged at login time. A useful signal is whether an investigator can answer the access-why question without chasing multiple teams.
Escalation / exception: Escalate any recurring break-glass use that lacks post-event review, because repeat exceptions usually mean the control design is compensating for a process flaw rather than an operational necessity.
Practitioner takeaway: The goal is not perfect restriction, it is defensible visibility into access decisions, because that is what lets a hospital prove control, reconstruct incidents and retain trust under regulatory scrutiny.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 — Outcomes Are Monitored | NIS2 evidence gaps are a governance and oversight problem. |
| Recommendation — Establish evidence checks that confirm access controls operate as intended. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Access proof depends on auditable events for record opens and privileged use. |
| IA-2 — Identification and Authentication (Organizational Users) | MFA proof and user authentication are central to the control evidence issue. | |
| AC-6 — Least Privilege | Privileged and emergency access governance is part of the question's control failure. | |
| Recommendation — Log access, privilege use and emergency actions with enough detail to reconstruct events. Verify authentication outcomes and retain evidence that MFA was enforced where required. Limit privileged access and review any standing elevation that cannot be justified. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question is about proving access control operation under regulatory scrutiny. |
| Recommendation — Document and test access control rules, exceptions and review evidence. | ||
| NIS2 | ICT risk-management measures | NIS2 requires demonstrable security controls and accountable governance for essential entities. |
| Recommendation — Maintain evidence that access controls, monitoring and governance operate effectively. | ||
Practitioner Guidance
What to verify: Verify that you can produce a complete access evidence trail for a sampled set of records, including requester, approver, MFA state, privilege elevation, emergency access and revocation. If any of those steps cannot be reconstructed quickly, the control should be treated as untrusted until fixed.
Decision rule: If the hospital cannot show evidence for privileged or emergency access within the same system of record used for normal access, prioritise evidence capture and reviewability before adding more policy language. The issue is not the absence of control intent, it is the inability to prove control operation under pressure.
What practitioners underestimate: The hardest part is not usually the authentication technology, it is joining access, approval, logging and exception handling into one accountable narrative. Many hospitals have each component separately, but fail at the point where a supervisor or auditor asks for a single answer about who accessed what and why.
Practitioner takeaway: For NIS2, a hospital should design access control as a demonstrable operating process, not a documentation exercise, because unproven control is functionally the same as failed control when accountability is tested.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org