Shared logins break the chain between action and person. When multiple clinicians or staff use one account, the audit trail can no longer prove attribution, which makes access review, incident investigation and regulatory inspection far harder. In hospitals, that is not just inconvenient. It is a governance failure in the identity record itself.
Why shared logins break access review in a hospital
Shared logins turn review into guesswork because the reviewer is no longer certifying a person’s access, only the existence of an account that several people can use. In healthcare that matters immediately: staff turnover, shift changes, agency workers and emergency coverage all make it easy for account use to drift away from the stated owner.
Without a one-to-one link between account and clinician, the review no longer tests whether the right person still needs access, whether the access was used appropriately, or whether a removed employee still has a path back into the record system.
The supervisory issue is not just that the audit trail is thinner. The deeper problem is that the control objective itself changes. Access review is supposed to support accountability, segregation of duties and timely revocation; a shared login can satisfy the form of the review while defeating its purpose. That is why shared credentials are a governance problem, not just a convenience problem. IAM and IGA Basics Access Reviews and Certification Guide
What breaks when the audit trail cannot name a person
Access review depends on three things: a known account owner, a current business justification and evidence that access matches actual job need. Shared logins disrupt all three. The reviewer cannot tell whether the account was used by a nurse, a doctor, a contractor or a night-shift replacement, so certification becomes a statement about infrastructure, not supervision.
That loss of attribution also weakens incident response. If a chart was viewed inappropriately, or an order was placed unexpectedly, the organisation cannot reliably answer who acted, under whose authority, and whether the use was legitimate. In regulated care settings, that ambiguity is especially damaging because supervisory review is meant to prove control over who can see or change patient data.
When the same login is reused across people, the organisation also loses the ability to detect excess access, dormant access or access that should have been removed after a roster change. NHI Lifecycle Management Guide Role Mining and Role Design Guide
Why healthcare supervision treats shared accounts as a control failure
Healthcare access is not only about whether someone can get in, it is about whether the organisation can prove it supervised that access properly. Shared logins erase the evidence needed for certification, so the review cannot reliably support least privilege, separation of duties or time-bound revocation. That creates a supervisory blind spot even if the technical access still works.
In practice, shared credentials also make remediation hard. If a reviewer flags a problem, the organisation cannot rotate the account for one user without disrupting everyone else, and it cannot selectively remove access from one clinician without changing workflow for the group. The result is usually either over-retention of access or informal workarounds that keep the account alive.
That is why shared accounts are usually a sign that the identity model does not match the operating model. The review process is asking a governance question, but the environment is answering with an operational shortcut. Joiner-Mover-Leaver (JML) Guide Segregation of Duties (SoD) Guide
Risk and Threat Considerations
Shared logins increase both governance risk and security exposure because they hide who actually performed a sensitive action. In a clinical environment that can mask inappropriate record access, make malicious use harder to investigate, and slow containment when an account is abused or reused outside its intended shift or team.
Failure mechanism: One credential is used by multiple people, so the audit trail records the account, not the actor. That breaks attribution, weakens recertification, and removes the evidence needed to prove that access was appropriately supervised.
Impact: Access reviews become less defensible, incident investigations lose precision, and the organisation may be unable to show who viewed or changed patient information. Over time, the shared account can become a permanent exception that normalises weak governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Shared logins undermine attributable audit evidence needed for review and investigation. |
| IA-2 — Identification and Authentication (Organizational Users) | Healthcare access review depends on a distinct authenticated user, not a pooled shared login. | |
| AC-2 — Account Management | Shared accounts break account ownership, review, and revocation discipline. | |
| Recommendation — Log individual actions so each sensitive access can be tied back to a person or delegated actor. Require individual user authentication for systems that handle clinical or patient data. Assign accountable owners to every account and review them on a defined schedule. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control must support accountable, reviewable access rather than pooled credentials. |
| A.8.15 — Logging | Logs must support attribution, especially where shared accounts weaken traceability. | |
| Recommendation — Define and enforce access rules that preserve individual accountability. Record activity at a level that preserves user attribution for reviews and investigations. | ||
Practitioner Guidance
What to verify: Treat any shared clinical account as a supervisory exception until you can prove a compensating control. The minimum evidence is a named owner, a documented business purpose, and a control that records individual actions outside the shared login.
Decision rule: If the account can access patient data or write clinical records, do not certify it on account existence alone. Certify the people behind the access, or replace the shared login with individually attributable access before the next review cycle.
What good looks like: A reviewer can trace each sensitive action to a person, each account has a clear owner, and removal of one user does not require leaving the shared credential in place for everyone else.
Practitioner takeaway: In healthcare, the problem with shared logins is not merely weak logging, it is that supervision itself stops being meaningful once the account is no longer tied to a single accountable person.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org