One family, one login: the parent portal problem

Two parents share a password, a grandparent has it, a custody order changed, and nobody revoked anything. Why unique user identification is the one requirement with no judgment call in it, and how to run a portal that survives a real family.

Last verified: 2026-07-12

The intake coordinator sets up the portal, emails the login to the mom, and the family does what every family does: mom gives the password to dad, dad gives it to the grandmother who does pickups, and the babysitter has it written on the fridge because she is the one who checks the schedule.

A year later, the parents separate. A court order limits one parent’s access to records. The clinic dutifully notes it. And nothing at all changes, because there is no account to revoke. There is a password, and it is in four people’s phones.

The one requirement with no judgment call in it

Almost everything in the Security Rule invites you to assess, decide, and document. This one does not.

Unique user identification is a required implementation specification (45 CFR 164.312(a)(2)(i)): assign a unique name or number for identifying and tracking user identity. Required means implement it. No assessment, no equivalent alternative, no “reasonable and appropriate for a clinic our size.” It is the one place in the technical safeguards where the rule simply tells you what to do.

Shared logins are not a risk you accepted. They are a control you never had. And the failure cascades, because unique identity is what everything else stands on:

  • Authentication (45 CFR 164.312(d)) asks whether the person seeking access is who they claim to be. When four people are one account, the honest answer is that you do not know.
  • Audit controls (45 CFR 164.312(b)) require you to record and examine system activity. A log that says the family account downloaded the treatment plan at 11pm cannot tell you which family member, which is another way of saying you have logs and no audit trail.
  • Access establishment and modification (45 CFR 164.308(a)(4)(ii)(C)) assumes access can be modified. A household password cannot be modified; it can only be changed and redistributed, which is not the same thing at all.

Why families do this, and why the fix is not a lecture

Because you asked them to. One invite, one login, and a family that operates as a unit will use it as a unit. The parent who forwards the password is not being careless; they are solving the problem your onboarding created.

“Shared logins are not a risk you accepted. They are a control you never had.”

So the fix is upstream, in the invite flow, not downstream in a policy nobody reads:

One account per adult, by name. At intake, ask who needs portal access: both parents, a guardian, a grandparent who manages appointments. Each gets their own invitation to their own email address. It costs the coordinator two extra minutes and it is the entire ballgame.

Say why, in one sentence. Families accept this immediately when told the truth: separate logins mean we can see who accessed the record, and we can turn off access for one person without disrupting anyone else. Nobody argues with that.

Never send a password. Invitation links, self-set credentials, and multi-factor authentication where the platform offers it. If your portal cannot do per-person invitations, that is a real finding about your platform, and it belongs in your risk analysis rather than in a workaround.

Custody, which is the reason this actually matters

A parent is generally the personal representative of an unemancipated minor, and a personal representative is treated as the individual for privacy purposes (45 CFR 164.502(g)). Both parents usually hold that status, and both usually get access; a separation alone does not change it.

But it can change. A court order can limit one parent’s authority over health decisions or records. State law governs the details, and it varies. And the rule itself contemplates declining to treat someone as a personal representative where the clinic reasonably believes the individual has been or may be endangered by that person and it is not in the child’s best interest (45 CFR 164.502(g)(5)), a judgment that must be made carefully and documented.

Here is the operational point, and it is the whole reason for the section: whatever the legal answer turns out to be, you have to be able to implement it. A clinic that concludes, correctly, that one parent’s portal access must end, and then discovers there is nothing to end because the credential belongs to a household, has done the legal analysis and failed the practical one. Access tied to a person can be revoked in ten seconds. Access tied to a family cannot be revoked at all.

Related, and routinely missed: a parent may request confidential communications, that you contact them by a particular method or at a particular address (45 CFR 164.522(b)), and a provider must accommodate reasonable requests without demanding a reason. In a household in conflict, that request is not an inconvenience; it is often the point. Build the intake field for it.

The access request is not the portal

One clarification, because clinics conflate these. Portal access is a convenience you provide. The right of access is a legal obligation (45 CFR 164.524): a parent, as personal representative, may request the child’s records from the designated record set, and you must respond within 30 days, in the form requested where readily producible.

Giving someone a portal login does not satisfy a records request, and taking away a portal login does not extinguish the right. If a parent whose portal access you have limited makes a lawful access request, that request gets evaluated on its own terms, under 164.524, and denied only on grounds the rule actually permits.

The five-minute audit

Open your portal’s user list right now and answer three questions.

Is every account attached to one named human with their own email address? How many accounts belong to families who left the clinic a year ago? And if a parent called this afternoon with a court order, could you revoke exactly one person’s access, today, and prove afterward who had seen what and when?

If those answers are uncomfortable, nothing has gone wrong that a Tuesday cannot fix. It is a stale invite flow and an access list nobody has reviewed, and both are ordinary problems with ordinary solutions. The problem only becomes serious the day a family is in crisis and you need the access control that was never actually there.

The short version

  • Unique user identification is required, not addressable: every person who accesses PHI gets their own credential, with no assessment and no alternative.
  • A shared family login means your audit trail cannot answer who saw what, which quietly defeats audit controls too.
  • Custody changes are access changes: an account tied to a person can be revoked, an account tied to a household cannot.
  • A parent is generally the child's personal representative and stands in the child's shoes, but that status can change, and access must be able to change with it.
  • Fix the invite flow, not the family: one account per adult, named, revocable, and reviewed when the family situation changes.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Access tied to a person, not a household.

Named accounts, revocable on the day the situation changes, with a trail that can answer who saw what. WiseUpHIPAA holds the access picture for your clinic and shows you honestly where it drifted.