Minimum Access, Separate Accounts, and the Problem With Shared Logins
The Small Practice Stack Views 2

Minimum Access, Separate Accounts, and the Problem With Shared Logins

This article explains why small behavioral-health practices should use separate accounts and minimum necessary access for AI tools, and how to implement the discipline without excessive overhead.

Shared logins are a common shortcut in small practices. One username and password for the front-desk computer, one generic account for a vendor portal, one set of credentials passed from the departing staff member to the new hire. The shortcut feels efficient until the practice needs to know who accessed what, when a staff member leaves, or when an audit asks for individual accountability. AI tools amplify the problem because their outputs and logs often carry residual data that the practice may later need to explain.

This article explains why separate accounts and minimum necessary access are non-negotiable once any external AI tool enters the environment, and how a five-to-fifteen-person practice can implement the discipline without adding heavy administrative overhead. The methods described here are deliberately lightweight. They do not require new software or dedicated security staff. They do require consistent attention at the moments of onboarding, role change, and departure.

Why Shared Logins Break Defensibility

A shared login destroys the ability to attribute actions to a person. When an AI-generated checklist is approved, a patient message is sent, or an exception is ignored, the practice cannot later say who performed the step. That gap becomes costly the moment a question arises from a clinician, a patient, or an outside reviewer.

Shared credentials also complicate offboarding. When a staff member leaves, the practice cannot simply disable one account. It must change a password that others are still using, or risk leaving an active credential in the hands of someone who no longer works there. Either option creates operational friction and residual risk.

In the context of AI tools the problem is sharper. Many platforms retain prompts, outputs, or usage logs. If those records are tied to a shared account, the practice loses the ability to reconstruct individual activity. The decision record may say that human review occurred. The system logs cannot confirm who performed it.

Creating individual account for AI tool with minimum necessary access

Minimum Necessary Access as the Default

The principle of minimum necessary access is familiar from HIPAA conversations. Applying it to AI tools means each user receives only the permissions required for their specific role in the approved workflow. A front-desk staff member who initiates the three-field checklist does not need the ability to change prompt templates or export full conversation histories. An operations lead who reviews exceptions may need broader visibility, but still not unrestricted administrative rights.

We implement this by creating individual accounts at the moment a person is trained on the workflow. The account is tied to the person’s role, not to a generic function. When the person changes roles or leaves, the account is disabled rather than reassigned. Reassignment is treated as a new access decision that requires its own short record.

Practical Steps That Fit Small-Practice Capacity

The administrative cost of individual accounts is real but manageable. We keep a simple access log that lists each AI-related account, the person it belongs to, the date it was created, and the date it was disabled. The log lives in the same shared folder as the decision records. Updating it takes less than a minute when someone is onboarded or offboarded.

We also prohibit the creation of generic or departmental accounts for any AI tool that processes practice data. If a vendor interface requires a single administrative login, that login is held by the operations lead and used only for configuration and access management, never for daily workflow steps. Daily work always occurs under individual credentials.

AI tool access log used during staff offboarding in small practice

Reviewing Access When Someone Leaves

Offboarding is the moment when shared-login habits become most visible and most risky. Our checklist for AI-related access includes three actions that must be completed on or before the last day:

  1. Disable the individual’s AI tool account.

  2. Confirm that no shared credentials were in use for the same systems.

  3. Note the disable date in the access log and in the relevant decision record if the person’s departure affects an active pilot.

These steps are simple. They are also easy to skip when the departure is abrupt or the remaining staff are stretched. Writing them into the standard offboarding checklist makes them harder to overlook. We also review the access log quarterly even when no departures have occurred. The review takes only a few minutes and occasionally surfaces accounts that were never disabled after a role change or a short-term project.

The combination of individual accounts, minimum permissions, and a living access log creates a lightweight but usable trail. When a question later arises about who approved a particular AI-generated checklist or who last adjusted a prompt template, the practice can answer from its own records rather than from vendor logs or imperfect memory.

That’s a judgment call, not a tool question. Shared logins feel like a small efficiency until the practice needs to demonstrate individual accountability. Separate accounts and minimum access are the operational expression of the principle that the tool doesn’t sign the note—specific people do. Maintaining that specificity requires a modest ongoing discipline. The alternative is a system whose own records cannot answer basic questions about who did what.

Slow is not the same as behind. Taking the time to create and later disable individual accounts has consistently proven less costly than reconstructing activity after a shared credential has already blurred the trail. Practices that treat access hygiene as optional often discover the cost only when they need the trail and find it missing.

Comments

No comments yet — be the first to share a thought.

Leave a comment

Last Updated:2026-09-28 16:48