Because clinicians respond to delay by bypassing the approved path. When access takes too long, users improvise with shared logins, personal devices, or incomplete handoffs, which weakens accountability and makes audit trails unreliable. The risk is not the shared device itself, but the governance gap between workflow pressure and control design.
Why slow shared access turns into a compliance problem
Shared mobile devices are not the problem by themselves. The compliance risk appears when the workflow is slow enough that people start taking shortcuts to keep care moving. At that point, the control design no longer matches the operational reality, and the organisation loses confidence that access was granted to the right person, at the right time, for the right reason.
When that gap opens, the issue is usually not a single policy breach. It is a pattern of behaviour under pressure: users borrow logins, pass devices hand to hand, or leave sessions open because the approved path is too slow to be practical. Those workarounds weaken accountability, blur ownership, and make it harder to show who accessed what and when.
In practice, this is a governance and auditability failure more than a device-management failure. A shared device can be compliant if access is tightly controlled, timely, and traceable. It becomes risky when the delay makes the compliant path unreliable and staff begin treating the exception as the normal operating mode.
Where accountability and audit trails break down
Compliance frameworks care about traceability, least privilege, and trustworthy records. If several people use the same endpoint and access is slow, the environment can no longer prove that the logged-in user was the same person who performed the action. That undermines audit trails, incident reconstruction, and any control that depends on clear user attribution.
This is especially damaging in clinical settings because shared devices often sit inside fast-moving handoff processes. If authentication or reauthentication is sluggish, the next user may inherit an open session or reuse a prior session to avoid delay. The log may still show activity, but the evidence no longer reflects the real operator with enough precision for compliance review.
That is why the CIS Controls v8 emphasis on account management, access control, and audit logging matters here: the control objective is not only to limit access, but to preserve reliable attribution when work is shared and time-sensitive.
Why the control gap gets worse at scale
The risk compounds when many users, shifts, or locations rely on the same shared device pattern. A small amount of friction becomes a repeated incentive to bypass policy, so the organisation sees more shared credentials, more informal handoffs, and more inconsistent session handling. The more often that happens, the less believable the control environment becomes to auditors and internal investigators.
Mobile workflows also tend to cross policy boundaries faster than desktop workflows. Users may move between wards, rooms, or even organisations, which makes it easier for a delayed login to become a practical exception. Once that happens, the compliance issue is no longer whether the rule exists, but whether the rule can be followed reliably enough to matter.
Mobile access controls are therefore only as strong as the user experience around them. If the access path is slow or unreliable, even a technically sound policy can fail operationally because people will optimise for task completion rather than policy adherence. That is the real scale risk: repeated exceptions eventually look like the standard process.
Risk and Threat Considerations
Shared mobile devices increase exposure when delay pushes users toward workarounds that weaken attribution, session control, and credential discipline. The compliance impact grows because those shortcuts create ambiguous records and can let one person's access appear to be another person's activity.
Failure mechanism: Slow or unreliable access encourages shared logins, session reuse, and informal handoffs, which break the link between the individual, the device, and the action in the audit trail.
Impact: Investigations become harder to defend, evidence quality drops, and the organisation may be unable to demonstrate that access was authorised and properly attributed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Shared-device bypass risk depends on account sharing, session control, and traceable access. |
| Recommendation — Restrict shared access paths and review account usage so actions remain attributable. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Auditability is central when shared access and delayed logins weaken attribution. |
| Recommendation — Define and retain the audit events needed to reconstruct shared-device access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access Control | The issue is a control-design gap between access governance and clinical workflow pressure. |
| Recommendation — Align access rules with the required level of control over shared endpoints. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Delayed access drives policy bypass unless authentication and access control are reliable. |
| Recommendation — Tune authentication and access control so users do not bypass approved paths. | ||
Practitioner Guidance
What to prioritise: Measure the delay points that trigger bypass behaviour, not just the policy itself. If users are consistently forced into exceptions at login, reauthentication, or handoff, the control is operationally failing even if it looks sound on paper.
What to verify: Confirm that every shared-device workflow preserves a clear user-to-action trail, even during shift changes and urgent care scenarios. If attribution depends on a person remembering to log out or hand over properly, the control is too fragile for compliance use.
Decision rule: If the approved path cannot be completed fast enough for real workflow pressure, redesign the access path before adding more rules. Faster, more reliable access with strong attribution is usually better than a stricter process that users routinely bypass.
Practitioner takeaway: The compliance risk comes from forcing people to choose between speed and policy, because they will choose speed unless the compliant path is also the practical path.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org