Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when break glass access to…
Governance, Ownership & Risk

Who is accountable when break glass access to patient data is granted outside normal approval flows?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with the organisation that defines, approves, and monitors the emergency access process. Break glass access must be limited, time bound, logged, and reviewed after use. Security, IAM, and clinical governance teams should agree on who can trigger it, what conditions justify it, and how exceptions are investigated and reported.

Why This Matters for Security Teams

break glass access is not a routine privilege grant. It is an emergency control that temporarily overrides normal approval flows, so accountability must be explicit before the first use. In healthcare and other regulated environments, the real risk is not only unauthorised access, but also unclear ownership after the fact, when investigators cannot tell who authorised the exception, who monitored it, and who accepted the residual risk.

That is why emergency access should be treated as a governed security decision, not a convenience feature. The same discipline that applies to NHI controls also applies here: excessive privilege, weak logging, and poor review create durable exposure. NHIMG has shown that 97% of NHIs carry excessive privileges, which is why standing access assumptions fail fast under pressure, as outlined in the Ultimate Guide to NHIs. External guidance such as the OWASP Non-Human Identity Top 10 reinforces the same theme: access must be constrained, attributable, and reviewable.

In practice, many security teams encounter accountability gaps only after an emergency access event has already been used and no one can reconstruct the approval path.

How It Works in Practice

Accountability for break glass access should follow the organisation that owns the policy, approves the exceptions, and operates the monitoring. In practice, that usually means three groups share different duties: security defines the control requirements, IAM or platform teams enforce technical safeguards, and clinical governance or operational leadership approves who may trigger emergency access and under what conditions. The accountable owner is the function that can answer for the decision and the process, not just the person who clicked the button.

Operationally, a sound break glass process includes time-bound access, mandatory reason capture, strong authentication, full audit logging, and immediate post-use review. This aligns with the control intent found in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where emergency access must still preserve auditability and least privilege. The implementation lesson is similar to NHI governance: short-lived access reduces exposure, but only if logs are complete and review is independent. NHIMG’s 52 NHI Breaches Analysis shows how often compromised identities become a persistence mechanism when access is not tightly bounded and visible.

  • Define a single accountable owner for the emergency access program.
  • Require named approvers or pre-authorised trigger conditions for activation.
  • Issue access for the minimum time needed, then revoke automatically.
  • Log the request, justification, identity used, data accessed, and reviewer outcome.
  • Escalate exceptions into incident, compliance, or patient safety review when misuse is suspected.

These controls tend to break down in distributed care settings where multiple systems, vendors, and after-hours teams each believe another party owns the audit trail.

Common Variations and Edge Cases

Tighter emergency access often increases response overhead, requiring organisations to balance speed of care against control rigor. That tradeoff is real, especially when clinicians need immediate data access during a life-threatening event. Best practice is evolving, but current guidance suggests the answer should not be “everyone can break glass.” Instead, organisations should use narrowly defined scenarios, pre-approved thresholds, and retrospective review to keep the control defensible.

There are also edge cases where accountability must be layered. In a shared service, the health system may own policy while a third-party platform operates the mechanism. In that case, the provider may be operationally responsible for uptime and logging, but the healthcare organisation remains accountable for who is permitted to use the exception and how misuse is reported. For NHI-adjacent emergency paths, the same rule applies: human authority can delegate execution, but not accountability. The governance baseline in the Ultimate Guide to NHIs — Key Challenges and Risks is useful here, because emergency access becomes dangerous when privilege is broad, opaque, or poorly rotated after use.

When the environment spans multiple jurisdictions, vendors, or clinical domains, there is no universal standard for this yet. Organisations should document the accountable executive, the approving function, the review cadence, and the escalation path before an emergency occurs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Emergency access still needs least-privilege and controlled authorization.
OWASP Non-Human Identity Top 10NHI-03Break glass paths often rely on secrets and privileged NHI credentials.
NIST SP 800-53 Rev 5AC-2Accountable access provisioning and revocation are central to break glass governance.
NIST Zero Trust (SP 800-207)AC-6Zero Trust requires continuous evaluation even for emergency exceptions.
NIST AI RMFGovernance and accountability are core to risky automated or exception-based access decisions.

Treat emergency access as a privileged NHI path and rotate or revoke credentials after use.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org