Industries · Healthcare & Life Sciences

PHI reachable by identities nobody owns

Healthcare runs on integrations. EHR interfaces, imaging pipelines, claims clearinghouses, research environments and analytics platforms all authenticate as non-human identities, and each one accumulates access that outlives the project that created it. HIPAA holds you accountable for access to ePHI, but the access is granted by scope strings nobody reviews.

The question behind the budget

“Which identities can reach patient records — and who signed off on that?”

Regulated data at stake PHI · ePHI · clinical research data
Frameworks you evidence against
HIPAA Security RuleHITRUSTSOC 2ISO 27001
What makes it different here

How the risk takes shape.

01

The integration estate is the attack surface

Every EHR interface, HL7 feed, imaging gateway and claims connector authenticates as a service principal or managed identity. They are provisioned during implementation projects, granted broad access to move fast, and then run untouched for years.

02

Research and clinical share a tenant

De-identified research environments routinely sit in the same subscription hierarchy as clinical systems. An identity scoped at the subscription reaches both — and inherited access is exactly the kind that never appears in an access review.

03

Minimum necessary is an access question

The HIPAA minimum necessary standard is a statement about reach. Answering it requires knowing what each identity can actually get to, resolved through inheritance — not what its role is named.

Recurring patterns

What we look for first.

These are structural patterns this operating model tends to produce — not findings from any particular organization. They are where an assessment starts, because the architecture makes them likely.

Whether they are present in your estate is an empirical question. That is the point of looking.

  • Managed identities for imaging and archival workloads holding storage ownership across clinical and research data
  • Integration service principals with subscription-scoped Contributor rather than resource-scoped roles
  • Vendor and implementation-partner identities that survived go-live
  • Long-lived credentials on interface engines with no expiry and no owner
  • AI agents introduced for clinical documentation and coding, reaching PHI through inherited scope
What an assessment produces

Evidence, in your framework's language.

The reach set

Every identity that can reach your phi, with the path each one takes — direct, inherited, nested, eligible or federated.

Control-mapped findings

Findings tied to the control families you evidence against — HIPAA Security Rule and HITRUST — with the underlying facts attached.

One ranked decision

Not a backlog. The single highest-consequence move, with its projected outcome labeled as projected and its evidence trail intact.

Get started

Test these patterns against your own estate.

A scoped, read-only assessment on a subscription you choose. We answer the question above with your numbers, and tell you plainly where we could not determine something.

Free forever on a bounded estate · 30-day trial unlocks everything · No credit card

Read-only access · No agents · No log ingestion · Azure generally available