Integrations & data · Practice guide

Check access has ended across connected systems

Illustrative situation

A central account is disabled but an integrated application still permits access through an existing session or separate login. Disabling one login does not establish the result in every connected application. Some routes may need additional action. Agree the intended outcome and ask suppliers to demonstrate it through authorised testing.

Healthcare booking calendars on two connected screens with blue and orange appointment cards.
Make the handover between tools clear for the team using them.

What this means for your practice

Ask suppliers to demonstrate the agreed deactivation behaviour across relevant access paths. Record exceptions and the additional steps the organisation must take.

An example to discuss with your team

Deactivate a fictional test account and inspect the authorised test access paths.

Healthcare data integration connecting two applications through a field-mapping board.
Agree what each field means and which system owns it.
Healthcare data validation separating matched records from an exception tray.
Make rejected or uncertain records visible for review.

Questions to take to your supplier

Deactivate a fictional account and inspect relevant login paths and existing sessions in the test setup. Record any extra steps and their owners. Your team needs confirmation of the actual access change, not only a central account marked inactive.

Agree the working process

Build the review around the ways the person can actually reach connected services. A central login, a separate application account and an existing session may be handled differently by the specific products, so ask suppliers to demonstrate the required behaviour in an authorised test setting. The organisation should decide the intended deactivation outcome and who confirms it. Record applications that need additional manual steps, with clear owners and completion evidence. Do not assume a central inactive label proves every route has ended.

Use a fictional account and preserve the test boundaries so real staff access is not disrupted. Include a case where one application is unavailable during the change and must be checked later. Keep that exception open rather than declaring the whole process finished. Review the connected-system inventory when new tools are introduced. An access process can work correctly for the systems it knows about while missing an application that was never added to the list.

How to check the result

Track systems whose deactivation has not been confirmed.

Turn reading into a next step

Your action checklist

Work through these checks with your team or supplier. Tick the ones you have resolved and leave unknowns open.

Checks to discuss

Record what you know, what is still missing and the answer you need from your team or supplier.

Use project decisions only, without personal, patient or confidential details. Entries stay in this page and are not submitted to Kay & Co. Copy or download before leaving; this page does not save your notes.

Further reading

These sources provide background for the topic. The practice examples and checklist are illustrative planning suggestions from Kay & Co.

Related guides

Need help with this?

Tell us what is getting in the way. Kay & Co. can help you understand the options and turn the next step into something that works for your practice.

Explore integrations & data services or discuss your project.

Try the free Healthcare Digital Planner to find your starting priority.