Almost every small office we walk into has one: a single account that everybody uses. The front desk login. The shared clinical workstation. The office@ mailbox three people have open.
It exists for a good reason. Individual logins felt slower, and somebody made a practical decision years ago that nobody has revisited. It is worth revisiting.
What does a shared login actually cost?
You lose the ability to answer the question “who did that?”
Not in a blame sense. In a factual sense. Every log entry says the same username, so the audit trail records that the office did something, which you already knew.
That matters in four situations, and they are not hypothetical:
- Something was deleted or changed and you need to know how. Was it a mistake, a misunderstanding of the process, or someone acting deliberately? With a shared account you cannot tell, and the difference determines what you do next.
- Someone leaves. You cannot disable a shared account without disrupting everyone still there, so the credential the departing employee knows stays valid. In practice it often stays valid for years.
- You need to prove access control. Regulated sectors expect it. The HIPAA Security Rule asks for unique user identification and audit controls. A single shared account defeats both, and there is no way to argue otherwise after the fact.
- An account is compromised. With named accounts, you disable one person and investigate one mailbox. With a shared account, you have to change a password everybody depends on, in the middle of a working day, while trying to work out which of five people's activity was legitimate.
Why does nobody fix it?
Because the perceived cost is friction at the front desk, and the perceived benefit is abstract until the day it is not. That is a genuinely difficult trade to sell to a practice manager whose staff are already busy.
The good news is the trade is mostly false.
How do you fix it without slowing people down?
The goal is not “everyone types a long password constantly.” It is “the system knows who is at the keyboard, without anyone thinking about it.”
- Fast sign-in. A PIN or a fingerprint on a machine that has already verified the device is faster than typing the shared password, not slower.
- Fast user switching. Nobody logs out and back in. Sessions stay warm and switching is near instant.
- Shared mailboxes done properly. A shared mailbox in Microsoft 365 is not a shared account. Each person signs in as themselves and is granted access to the mailbox. Same inbox, same workflow, and every action is attributable. This one is free and takes about ten minutes.
- Kiosk accounts where they genuinely fit. A machine that only runs one non-sensitive application does not need per-person identity. Be honest about which machines those actually are — usually far fewer than claimed.
Start with the mailbox
If you do one thing, convert shared mailboxes to properly delegated ones. It is free, it takes minutes, it changes no one's daily workflow, and it immediately makes every action attributable.
Then work through the workstations. It does not have to happen in one weekend — each machine converted is one machine where the logs mean something.
The test
Ask yourself: if a patient record, a client file or a bank detail were changed tomorrow, could I find out who did it and when?
If the answer is no, that is not a security problem you have deferred. It is a question you have permanently given up the ability to answer.
Named accounts, enforced MFA and identity threat detection are part of every managed plan we run. If you would rather do the cleanup yourself and just want it done properly once, prepaid support hours cover exactly this kind of work.