Healthcare Identity Management Needs Organizational Ownership, Not Just IT

A cybersecurity consultant writes that healthcare organizations should view identity and access management as an enterprise risk rather than an IT-only responsibility. He reports that assessments are uncovering many more identity and access problems, with a large share rated critical or high risk. The piece outlines five questions to help assign ownership and reduce access risk.
A consultant with Fortified Health Security reports that healthcare reviews now uncover four times as many identity and access problems as they did a year earlier, with 64% rated critical or high severity. These issues involve people-related accounts for staff, contractors, vendors, and privileged administrators, as well as machine-based accounts tied to services, APIs, automation, and AI agents.
The piece says cleanup often stalls because the person responsible for fixing an account lacks authority to decide its purpose. Examples include unclaimed lab service accounts, vendor accounts outliving contracts, and permissions growing through acquisitions. It recommends treating the work as an identity-risk assessment and answering five questions, beginning with identifying an accountable owner by name.
Healthcare patients, clinicians, vendors, and administrators could be affected if identity and access risks remain unowned. Stronger organizational accountability may reduce exposure of sensitive systems and data, while unclear ownership could leave dormant or excessive access in place. Because care delivery depends on many connected applications and accounts, improvements or failures in identity governance may influence privacy, operational continuity, and trust in health services.