Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when a terminated employee still…
Governance, Ownership & Risk

Who is accountable when a terminated employee still has access to sensitive healthcare records?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Accountability usually spans identity, security, application, and business owners because access removal depends on each control working together. HR may trigger the termination, IAM teams may execute revocation, and application owners may need to confirm that ERP entitlements are removed. Effective governance assigns clear ownership and measurable deadlines for each step.

Why This Matters for Security Teams

A terminated employee retaining access to sensitive healthcare records is not just an IAM cleanup issue. It is a control failure across HR, identity governance, application administration, and auditability. In healthcare, the risk extends beyond privacy exposure to patient harm, reportable incidents, and regulatory scrutiny. The problem is often not that access removal is impossible, but that ownership is fragmented and revocation timing is undefined.

NHI Management Group’s Ultimate Guide to NHIs notes that only 20% of organisations have formal processes for offboarding and revoking API keys, and 91.6% of secrets remain valid five days after notification. That stat is about machine identities, but the operational lesson applies here too: revocation delays are common when the process depends on handoffs instead of hard deadlines. In healthcare environments, that gap can leave EHR, ERP, and analytics access active after employment has ended.

OWASP’s Non-Human Identity Top 10 reinforces a broader governance truth: identity lifecycle failures become security incidents when revocation is incomplete or unverifiable. In practice, many security teams encounter stale access only after an audit exception, a privacy complaint, or an incident review has already exposed the gap.

How It Works in Practice

Accountability should be assigned by control point, not by assumption. HR owns the termination trigger, IAM owns account disablement, application owners own entitlement removal, and the business owner confirms that access no longer serves an operational need. For healthcare records, that means every system holding protected health information needs an explicit offboarding path, including direct application logins, delegated admin roles, SSO-linked apps, and break-glass accounts.

The strongest practice is a time-bound revocation workflow tied to a verified termination event. The workflow should define who acts, what must be removed, and how quickly each step must occur. Current guidance from NIST SP 800-53 Rev. 5 emphasizes access control, account management, and audit logging as separate but linked responsibilities. That matters because “disable the directory account” is not the same as removing access from the application itself.

A practical sequence usually looks like this:

  • HR issues the termination event and timestamps it.
  • IAM disables SSO, federation, and directory access immediately.
  • Application owners remove entitlements and privileged roles.
  • Security validates completion through logs, reports, or workflow evidence.
  • Compliance retains proof that revocation met policy and regulatory deadlines.

This is where lifecycle discipline matters. The NHI Lifecycle Management Guide frames the larger lesson correctly: identities must be governed from issuance through revocation, not just at creation. For healthcare records, the same lifecycle logic should apply to human access because stale privileges create the same audit and exposure problems as stale secrets. These controls tend to break down when records are accessed through multiple integrated systems because revocation in one platform does not automatically remove access everywhere else.

Common Variations and Edge Cases

Tighter offboarding often increases operational overhead, requiring organisations to balance rapid revocation against service continuity, on-call access, and application dependency mapping. That tradeoff is real in healthcare, where some accounts support clinical workflows, emergency access, or shared departmental functions. Best practice is evolving, but there is no universal standard for every edge case yet.

One common exception is the break-glass account. It should not be treated as ordinary user access, and it needs separate approval, monitoring, and post-use review. Another edge case is contractor or temporary staff access, where the employment end date may not match the actual access end date unless the identity governance workflow enforces it. Shared accounts are especially risky because a single termination event may not reveal who still knows the credential.

NHIMG research shows the broader pattern is systemic: Top 10 NHI Issues and related breach analyses show how quickly weak lifecycle control becomes visible only after damage. While that research focuses on NHIs, the operational takeaway is the same for human access in healthcare: if ownership is unclear, revocation is slow, and evidence is missing, accountability becomes disputed instead of enforced.

Where this answer breaks down most often is in organisations with many acquired applications, manual provisioning, or no authoritative entitlement inventory, because no one can prove that access was fully removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-06Lifecycle revocation failures mirror stale account and credential risks.
CSA MAESTROGOV-02Governance needs clear ownership for identity lifecycle actions.
NIST AI RMFGOVAccountability and oversight are core governance needs for access decisions.
NIST CSF 2.0PR.AC-4Least privilege and access management require prompt deprovisioning.
NIST SP 800-63Identity proofing and authenticator lifecycle inform secure offboarding.

Remove terminated-user entitlements quickly and confirm every dependent system is updated.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org