Who Can See What: Access Control for Small Clinics

The receptionist does not need the same access as the doctor. Here is how unique logins, the minimum-necessary rule, and same-day offboarding keep patient data — and your practice — safe.

Nurse reviewing patient information on a tablet

One Person, One Login — No Exceptions

The most common setup in small clinics is also the riskiest: one login for the front desk that everybody shares. It feels practical — people cover each other’s shifts, the computer stays logged in all day, nobody gets locked out during a rush.

The problem is accountability. When five people share one login, you cannot tell who looked at what. If a record gets changed, snooped on, or emailed somewhere it should not go, the audit trail just says “front desk did it” — which tells you nothing. HIPAA expects you to know who accessed patient information, and shared logins make that impossible.

There is a second problem: passwords travel with people. When someone who knew the shared password leaves — on good terms or bad — they still know the password. Now you have to change it everywhere and tell everyone, which nobody does promptly, which means the ex-employee effectively still has access. Unique logins end that cycle: one person leaves, you disable one account, done.

Minimum Necessary: Give People What the Job Needs

HIPAA’s Privacy Rule includes a standard called “minimum necessary”: staff should be able to see the patient information they need to do their jobs, and not much more. This is not about distrust — it is about shrinking the blast radius. The fewer records each person can open, the less damage any one mistake or bad actor can do.

In practice, it looks like this. The front desk needs schedules, demographics, and insurance details — not clinical notes. The biller needs codes, dates of service, and payer information — not the full chart. Clinical staff need the chart — not the payroll system. Most EHR and practice management systems let you set these roles in an afternoon; the feature is usually already there, just never configured.

A good test: pick any employee and ask, “Could this person open the record of a patient they have never interacted with?” If the answer is yes and their job does not require it, their access is too broad. Tighten it and nobody’s day gets harder — they just stop seeing things they never needed.

The Friday Afternoon Problem: Revoking Access

Here is a scenario every practice owner recognizes. Someone gives notice — or is let go on a Friday afternoon. Monday comes, the office is busy, and disabling their accounts slides to “later.” Later becomes next week. Next week becomes never. Months later, that login still works: EHR, email, remote access, the alarm code nobody changed.

This is the single most fixable risk in access control, and it costs nothing. Make a one-page offboarding checklist and use it every single time someone leaves, whether they quit, were fired, or retired after twenty years:

  • Disable their EHR and practice management logins the same day — before they walk out, if it is a termination.
  • Disable their email account, or convert it to a shared inbox so nothing bounces while you redirect it.
  • Change any shared passwords they knew: Wi-Fi, alarm codes, the safe, shared logins you have not eliminated yet.
  • Remove remote access and collect keys, badges, and any practice-owned devices.
  • Check for email forwarding rules they may have set — a quiet forward to a personal address is rare but devastating.

Tape the list inside the office manager’s cabinet. The whole thing takes fifteen minutes, and it closes the most common way ex-employees keep reaching patient data.

Passwords People Can Actually Live With

Access control falls apart if the passwords are on sticky notes under the keyboard. The fix is not longer random strings nobody can remember — it is passphrases and a second factor. A passphrase like “correct-horse-battery-staple” style — four or five ordinary words — is both strong and memorable, which means people stop writing it down.

Then add multifactor authentication (MFA) everywhere it is offered: the EHR, email, remote access. MFA means a stolen password alone is not enough — the thief also needs the code from the employee’s phone. It is the cheapest, highest-impact safeguard in this entire series, and most systems already include it for free.

If your staff juggle a dozen logins, get a business password manager. One strong master passphrase, and the manager remembers the rest. It ends the sticky notes, the shared spreadsheets of passwords, and the “what was the login for the payer portal again” loop.

What to Do Monday Morning

Make a simple list: every system that holds patient data, and who has a login to each. EHR, email, billing software, payer portals, remote access, the alarm. Then ask two questions: does anyone on this list no longer work here, and does anyone have access they do not need for their job?

Disable the ex-employee accounts today — not this week, today. Then turn on MFA on your own email and EHR logins before lunch. You will have closed the two biggest access gaps in the practice before noon.

Not sure where your practice stands?

Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

What does “minimum necessary” actually mean?

It is a HIPAA Privacy Rule standard: when staff use or share patient information, they should limit it to what is needed for the job at hand. The front desk scheduling a visit does not need the clinical notes; the biller posting a claim does not need the full chart.

Can two people share one login if they work the same desk?

No. Shared logins destroy accountability — if something goes wrong, you cannot tell who did it. They also survive employee departures, since the password walks out the door with the person. Give everyone their own login; it costs nothing.

How fast should we disable accounts when someone leaves?

Same day, every time. For a termination, disable access before the person leaves the building. For a resignation, do it on their last day. A login that works for one extra week is a login an ex-employee can use.

Do we need fingerprint scanners or anything fancy?

No. Unique logins, sensible roles, prompt offboarding, and multifactor authentication cover what a 10-to-25-person clinic needs. Fancy hardware is a distraction until the basics are done.

What about the doctor logging in on the shared front workstation?

Set the computer to lock automatically after a few minutes idle, and build the habit of locking it manually — Windows key + L, or Control-Command-Q on a Mac. An unlocked workstation with a doctor’s session open is an open chart on the counter.