Blog
The Hidden Cost of “Good Enough” Governance
Manual workarounds produce the paperwork of governance without the control. The bill comes later. In a...
When two health systems combine, the announcement talks about scale, coverage, and patient outcomes. What it does not mention is that on the first day of combined operations, the acquiring organization becomes responsible for thousands of people it has never onboarded. Those people use dozens of clinical applications the identity team has never seen and rely on directories it does not control. In identity governance terms, the deal does not create a bigger, cleaner program. It creates an immediate and largely invisible gap. Identity is often the first thing to break when a health system acquires another, and the last thing anyone budgets for.
One of the recurring challenges in healthcare identity is the large number of departmental and legacy clinical applications that never make it into the governance platform. As we’ve explored earlier in this series, these disconnected systems create blind spots that organizations often manage by hand. An acquisition multiplies both problems overnight. Every unknown application in the acquired hospital becomes a new blind spot. Every manual process the acquired team relied on becomes the acquirer’s liability. The gap that took years to accumulate in one organization arrives all at once in another.
Most identity challenges build gradually. Acquisitions do not. They create complexity all at once when the transaction closes.
The application inventory is unknown. The acquired hospital runs its own clinical, departmental, and administrative systems, many of them legacy, and there is rarely a clean, current list of what they are or who has access to them. Discovery itself takes time.
The identity sources are different. The acquired organization has its own directory, HR system, naming conventions, roles, and entitlement model. Two people with the same job title may require entirely different access, and neither environment understands the other.
There is no integration path. The acquired systems were never built to connect to the parent’s governance platform, and the traditional way to connect them, one custom connector project per application, cannot move at the speed the situation demands.
And there is a clock. Regulators, auditors, and cyber-insurers do not grant a grace period because an integration is in progress. From day one, the combined entity is accountable for access it cannot yet see or control.
Under the traditional connector model, bringing an acquired hospital’s applications under governance is not a project measured in weeks. It commonly takes a year or more, and for complex environments the timeline stretches further. Each application is scoped, a connector is built or bought, data is mapped, and the whole thing is tested before it can be trusted to provision and deprovision access.
While that work proceeds, the access it is meant to govern sits in the state the acquisition left it. Accounts created under the old regime remain. Entitlements nobody has reviewed remain. The governance program can see the connected corporate systems clearly and the acquired clinical systems barely at all. For a year or more, a material part of the combined organization operates outside the controls that the rest of it takes for granted.
The sharpest edge, as it usually is, is offboarding. Acquisitions are followed by role changes, consolidations, and departures on both sides. Duplicate functions are merged. Transition contractors finish their work. Staff leave rather than move to the new organization. Each of these should trigger prompt removal of access across every system the person could reach.
Imagine a hospital acquisition closing on a Friday. On Monday morning, thousands of clinicians arrive at work with the same credentials they had before the acquisition. Some have changed reporting structures. Some are transitioning departments. Some contractors are finishing their engagement. Yet the acquiring organization’s identity team may not even know that many of those systems exist. That is exactly the environment in which manual offboarding becomes the organization’s weakest control.
Because the acquired applications are not yet connected, access removal falls back to manual effort, exactly the good-enough process this series has already questioned, now applied to systems the acquiring team barely knows. The acquiring team may not yet have administrative credentials for those systems. The result is a population of accounts that should be closed, in systems that are not yet governed, during the precise window when the organization is least able to track them. Standing access and standing risk peak at the same moment.
For a health system that acquires one hospital and stops, the integration burden is temporary, painful but finite. For a system that acquires several facilities a year, and many do, the model breaks in a different way. A new integration backlog arrives before the previous one is cleared. The team is perpetually a year or more behind the organization’s own growth. Under a connect-each-application-by-hand model, catching up is not a matter of effort. The math does not allow it.
The lesson of healthcare M&A is that the connectivity model itself, not the size of the integration team, is the constraint. An approach that can keep pace with acquisition looks different. It brings unfamiliar and legacy applications under governance in days rather than months, without a bespoke project for each one. It reconciles multiple identity sources into a trustworthy view of access across the combined organization. Most importantly, it automates provisioning and deprovisioning and verifies that those changes actually occurred.
Acquisitions are always hard. Identity doesn’t have to be the reason they stay hard for the next year. A connectivity model designed for acquisition changes the timeline from a year of exposure to something an organization can absorb as a normal part of growth. In an industry where consolidation is constant, that difference is not a convenience. It is the line between governance that scales with the business and governance that falls permanently behind it.
Health systems will keep acquiring. The question is whether identity keeps arriving late to every deal, or finally shows up on day one.
Insights, best practices, and real-world stories from the front lines of identity transformation.
Manual workarounds produce the paperwork of governance without the control. The bill comes later. In a...
A read-only connection tells you what access exists. Governance requires the ability to change it. ...