Shared Healthcare Workstations Without Shared Accounts
Published August 31, 2026
Featured image
- Concept: A healthcare employee signing into a shared clinical workstation with an individual account or identification badge. Show a realistic outpatient or senior-care environment without visible patient information, passwords, warning graphics, or hacker imagery.
- Filename:
shared-healthcare-workstations-individual-accounts.jpg - Alt text: Healthcare employee signs into a shared clinical workstation using an individual account and secure badge at a clinic
Healthcare employees often share computers. A workstation may be used by several nurses, medical assistants, front-desk employees, clinicians, or caregivers during the same day.
Sharing the device can be practical. Sharing one username and password is a different matter.
When several people use the same account, the organization may be unable to determine who opened a record, changed a setting, downloaded information, sent a message, or approved an action. It also becomes harder to remove access when an employee leaves or changes roles.
Quick Answer: Can healthcare employees share a workstation?
Yes. Employees can share a properly configured workstation while still signing in with individual accounts.
Each workforce member should use an identity assigned to that person. The device can remain shared, but access permissions, authentication, activity records, and account termination should follow the individual user.
A general account such as
FrontDesk
,
NurseStation
, or
ClinicUser
should not replace individual identification when people access systems containing electronic protected health information.
A shared device is not the same as a shared account
These two arrangements are often mistaken for one another.
Shared workstation
A shared workstation is one computer used by several authorized people. Each person signs in using an individual account, badge, passkey, security key, or another approved authentication method.
This arrangement can support:
- Individual accountability
- Role-based access
- Reliable activity records
- Prompt access removal
- Different permissions for different jobs
- Investigation of suspicious activity
Shared user account
A shared account uses one set of credentials for multiple people.
Examples include:
- Everyone at reception using
FrontDesk - Every caregiver using
CareTeam - A password taped near a nursing-station computer
- Several administrators using one Microsoft 365 administrator account
- Former and current employees knowing the same vendor password
The computer may be convenient to use, but the organization loses an important connection between the activity and the person who performed it.
HHS states that covered entities must assign a unique name or number to each workforce member who uses a system containing electronic protected health information so that access and activity can be identified and tracked.
That does not mean every healthcare application has identical technical capabilities. It does mean limitations and exceptions should be identified, assessed, documented, and addressed appropriately.
Why shared accounts create practical problems
Activity becomes difficult to attribute
Suppose a patient record is opened unexpectedly, an email-forwarding rule appears, or a large report is downloaded.
If ten people use one account, the activity log may identify the shared username but not the person responsible. Leadership may then have to rely on schedules, interviews, camera footage, or assumptions.
Individual accounts provide a much clearer starting point.
Passwords spread beyond their intended audience
Shared passwords tend to be:
- Written down
- Sent by text or email
- Reused
- Changed infrequently
- Known by former employees
- Disclosed to temporary personnel or vendors
Changing the password can disrupt everyone using the account, which encourages organizations to postpone the change.
Access removal becomes unreliable
When an employee leaves, disabling an individual account is straightforward. With a shared account, the organization must identify every person and device using it before changing the password.
That delay can leave former employees with continued access.
Permissions become too broad
A shared account usually receives enough permission for everyone who uses it. This often means some employees receive more access than their work requires.
Individual accounts allow permissions to follow job responsibilities more closely.
Multifactor authentication becomes awkward
MFA is difficult to manage when approval prompts are sent to one employee’s phone or several people share one authentication method.
Staff may begin approving prompts without knowing who initiated them. They may also create unsafe workarounds to avoid disrupting care.
The answer is not to abandon MFA. It is to design authentication around shared-device workflows.
Why this matters to healthcare organizations
Independent medical and dental practices
A front-desk workstation may connect to scheduling, insurance, billing, email, payment, and patient-record systems. One shared login can obscure activity across several sensitive workflows.
Hospice and home-health providers
Employees work from offices, homes, client locations, and mobile devices. Individual identities help the organization manage remote access and remove it when assignments change.
Assisted-living and senior-living organizations
Computers at nursing stations may be used across shifts. Fast access is important, but so is knowing which employee accessed or changed information.
Outpatient clinics
Clinicians and support personnel may move between rooms throughout the day. Authentication must be quick enough to support care while preserving individual accountability.
Small organizations with limited IT staff
Smaller organizations may believe shared accounts are necessary because account administration takes time. In practice, shared accounts often create more work during employee departures, access reviews, investigations, and password changes.
How to configure a safer shared-workstation workflow
1. Inventory shared computers
Create a list of computers used by more than one person.
For each device, record:
- Location
- Device owner
- Primary users or departments
- Applications accessed
- Whether ePHI may be displayed or stored
- Current sign-in method
- Automatic-lock setting
- Local administrator access
- Support responsibility
Include reception desks, nursing stations, treatment rooms, medication areas, back offices, and shared laptops.
2. Identify shared accounts
Look beyond the Windows login. Shared credentials may exist in:
- Electronic health records
- Microsoft 365
- Billing platforms
- Imaging systems
- Patient portals
- Laboratory services
- Pharmacy and prescribing platforms
- Vendor-support portals
- Network devices
- Backup systems
- Remote-access tools
Do not immediately disable an account simply because it is shared. First determine what depends on it and whether changing it could interrupt patient care.
3. Classify each account correctly
Not every non-person account serves the same purpose.
Account typeAppropriate general treatmentIndividual workforce accountAssigned to one person and tied to that person’s responsibilitiesShared human loginReplace where reasonably possible with individual accessService accountRestrict to a defined system function; do not use for routine human activityShared mailboxGive named users delegated access instead of sharing its passwordEmergency-access accountReserve for documented emergencies and monitor closelyVendor accountAssign named access where possible; restrict, review, and expire itKiosk accountLimit to a narrowly defined application and prevent broader access
A service account or kiosk identity should not quietly become a convenient staff login.
4. Give each employee an individual identity
Provision access using a repeatable onboarding process.
The account record should identify:
- Employee name
- Job or role
- Department or location
- Manager
- Approved systems
- Required permissions
- Authentication method
- Account owner
- Start date
- Review date
Permissions should reflect current responsibilities, not simply copy everything another employee has.
5. Choose authentication that fits the workflow
A busy clinical area needs a sign-in process that employees will actually use.
Depending on the environment and licensing, suitable options may include:
- Individual username and password with MFA
- Windows Hello for Business
- FIDO2 security keys
- Passkeys
- Badge-based authentication
- Microsoft-supported frontline-worker authentication
- Single sign-on with controlled session behavior
Microsoft recommends phishing-resistant methods such as Windows Hello for Business, passkeys, FIDO2 security keys, and certificate-based authentication where appropriate.
Microsoft also provides specialized shared-device and frontline-worker options. These require careful planning, licensing review, pilot testing, and configuration. They should not be enabled across an organization merely because they appear convenient.
6. Configure automatic locking
Shared workstations should lock after an appropriate period of inactivity.
The exact timing should reflect:
- Workstation location
- Likelihood of public or patient access
- Clinical urgency
- Application behavior
- Reauthentication time
- Care-continuity requirements
- Results of the organization’s risk analysis
An aggressive timeout that repeatedly interrupts documentation may encourage unsafe workarounds. A timeout that is too long may leave patient information exposed.
Test the setting with actual users and workflows.
7. Separate administrator access
Employees should not perform ordinary email, browsing, or clinical work while signed in with an administrator account.
Administrators should use:
- An individual everyday account
- A separate named administrative account
- MFA appropriate to the account’s risk
- Only the privileges needed for the task
- A documented procedure for elevated access
Microsoft recommends least privilege, MFA for administrators, and time-limited privileged access through Privileged Identity Management when licensing and operational needs support it.
8. Maintain emergency access separately
An emergency-access account—sometimes called a break-glass account—is not an ordinary shared staff login.
Microsoft recommends two cloud-only emergency-access accounts for Microsoft Entra environments. These accounts require deliberate configuration, protected credentials, strong authentication, monitoring, testing, and documented authorization.
They should:
- Be used only for defined emergencies
- Remain separate from normal staff activity
- Avoid dependencies likely to fail during the same emergency
- Generate alerts when used or changed
- Be reviewed and tested on a documented schedule
- Have credentials stored securely and accessibly to authorized personnel
Creating an emergency account and forgetting about it is not an emergency-access strategy. It is merely an unattended privileged account wearing a dramatic name.
9. Document exceptions and legacy limitations
Some clinical or vendor systems may not support individual accounts properly.
When replacement is not immediately feasible:
- Record the affected system and account.
- Identify who is authorized to use it.
- Document the operational reason.
- Restrict access by device, network, location, or schedule where possible.
- Limit permissions.
- Monitor relevant activity.
- Protect and rotate credentials.
- Establish a review date.
- Plan remediation, replacement, or compensating safeguards.
An unsupported application does not make the risk disappear. It makes documentation and risk management more important.
10. Test the complete employee lifecycle
A sound access process covers more than initial account creation.
Test what happens when an employee:
- Is hired
- Changes roles
- Transfers locations
- Takes extended leave
- Loses an authentication device
- Needs temporary elevated access
- Leaves unexpectedly
- Returns as a contractor
- Requires urgent access during an outage
The organization should be able to remove or change access without guessing which shared passwords the person may know.
What should healthcare leaders ask their IT provider?
Leadership does not need to configure every technical control. It should receive clear answers to these questions:
- Which shared user accounts exist?
- Which systems containing ePHI use them?
- Can activity be traced to an individual?
- How quickly is access removed after a departure?
- Who reviews administrator, vendor, and service accounts?
- How are shared clinical workstations secured?
- Which legacy systems prevent individual sign-in?
- What compensating measures are documented?
- When were emergency-access accounts last tested?
- Who owns each unresolved access risk?
A report consisting only of usernames is not enough. Leadership needs ownership, risk, status, and next actions.
Protect, Operate, Recover, and Grow
Protect
- Use individual workforce identities.
- Apply least privilege.
- Require appropriate MFA.
- Separate administrator accounts.
- Lock unattended workstations.
- Restrict service, kiosk, vendor, and emergency accounts.
Operate
- Maintain an account and device inventory.
- Use documented onboarding and offboarding.
- Review access after role changes.
- Give employees a quick, workable sign-in method.
- Document application owners and support contacts.
- Test shared-workstation settings in real workflows.
Recover
- Preserve sign-in and administrative records.
- Document how compromised sessions are revoked.
- Maintain emergency-access procedures.
- Know how staff will work during identity or Microsoft 365 outages.
- Record temporary access changes made during an incident.
Grow
- Replace shared human accounts systematically.
- Add individual authentication requirements to vendor evaluations.
- Retire applications that cannot meet operational and security needs.
- Improve role-based access as the organization expands.
- Use access-review findings to guide technology planning.
The bottom line
Healthcare organizations do not need to assign one computer to every employee. They do need to distinguish the device from the identity.
A shared workstation can support efficient care when each user signs in individually, permissions match job responsibilities, unattended sessions lock, and access is removed promptly.
Start with three actions:
- List the shared workstations.
- Find the shared human accounts.
- Prioritize the accounts that reach patient information, email, administration, billing, or remote access.
That creates a practical path forward without disrupting every workflow at once.
Frequently asked questions
Can two healthcare employees use the same computer?
Yes. A properly configured workstation can be used by multiple employees. Each employee should sign in with an individual identity so permissions and activity can be attributed appropriately.
Can employees share an EHR username?
HHS states that workforce members using systems containing ePHI must receive unique identification so activity can be identified and tracked. If a legacy system cannot support this, the organization should assess and document the limitation, apply safeguards, and establish a remediation plan.
Is a shared mailbox the same as a shared account?
No. A Microsoft 365 shared mailbox can provide several named users with delegated access. Employees should use their own accounts instead of sharing the mailbox password.
What is wrong with a nursing-station login?
A generic nursing-station account may prevent the organization from knowing which employee performed an action. The workstation can remain shared while staff use individual identities and a sign-in method designed for quick clinical access.
Should every Microsoft 365 administrator have a separate account?
Yes. Routine work and privileged administration should be separated. Each administrator should have an individual everyday identity and a separate named administrative account with appropriate protection.
Are service accounts allowed?
Service accounts can be necessary for applications, integrations, and automated processes. They should have a defined owner and purpose, limited permissions, protected credentials, monitoring, and a review process. Staff should not use them for ordinary work.
What is an emergency-access account?
It is a highly privileged account reserved for situations in which normal administrative access is unavailable. It requires special protection, monitoring, testing, and documentation and should never be used as a routine shared administrator login.
Strengthen your healthcare technology readiness
Vault Technologies helps healthcare organizations improve account administration, Microsoft 365 and endpoint management, shared-workstation configuration, access documentation, employee lifecycle procedures, and care-continuity planning.
Our nurse-led perspective keeps technical decisions connected to the realities of patient care, shift changes, mobile work, and busy clinical environments.
Request a complimentary Technology Health Assessment to establish a practical baseline across access controls, endpoint management, vendor dependencies, documentation, and recovery readiness.
The assessment is a planning tool. It is not a legal opinion, compliance certification, penetration test, forensic investigation, or guarantee against cyber incidents.
Authoritative sources
- HHS — “Does the Security Rule permit a covered entity to assign the same log-on ID to multiple employees?”, published April 8, 2010.
- HHS — Summary of the HIPAA Security Rule, updated August 7, 2026.
- HHS — Guidance on HIPAA and Cloud Computing, updated December 23, 2022.
- Microsoft — Manage emergency-access accounts in Microsoft Entra ID, updated June 5, 2026.
- Microsoft — Best practices for Microsoft Entra roles, updated June 1, 2026.
- Microsoft — Authentication methods in Microsoft Entra ID, updated May 7, 2026.
- Microsoft — Device management for frontline workers, updated October 24, 2025.
Recent Posts













