Agency staff and shared logins: the care sector's quiet audit failure
If you cannot say who changed a medication record, you have an accuracy problem before you have a security one. Regulators notice the accuracy first.
The pattern is almost always the same. A care home runs its records on one shared account because agency staff rotate through, the induction is short, and setting up a login for someone here for three shifts feels like effort nobody has time for. So everyone signs in as “Reception” or “Nurse1”, and the system dutifully records that “Nurse1” administered the tablets at 8am.
The trouble is that “Nurse1” is not a person. When a family, an inspector or a coroner asks who made an entry, the honest answer is that the record cannot tell you. That is not a data-protection footnote. Under the accuracy principle, a record you cannot attribute is a record you cannot fully stand behind, and in a regulated setting that is the part that bites.
It also removes your only real defence when something goes wrong. Individual logins are not there to catch staff out. They are there so that a good nurse can prove she did the right thing, and so that a genuine mistake can be traced to a training gap rather than left hanging over the whole team. Shared logins protect nobody, least of all the honest majority.
The fix is unglamorous and it works. Every person who touches a record gets their own account, agency included, created before their first shift and switched off after their last. It takes a few minutes per starter and a leaver process that actually runs. Most of the homes we check already have the software to do this - the accounts simply were never made.
If the objection is time, be honest about which time you mean. The five minutes to create a named login is real. The days lost reconstructing who did what after an incident, with a record that cannot help you, are far more real, and they always arrive at the worst possible moment.
- ✓Give every worker, agency included, their own named login before their first shift.
- ✓Run a leaver step that disables the account the day someone stops working there.
- ✓Check your records system can show who made each entry, and turn that on.
- ✓Ban the shared “ward” or “reception” account and delete it once everyone has their own.
- Accuracy and record-keeping under data protection law INFORMATION COMMISSIONER'S OFFICE ↗
- Cyber Essentials: user access control NATIONAL CYBER SECURITY CENTRE ↗
- Data security and protection in adult social care GOV.UK ↗
Links open each publisher’s live coverage of this topic.