Southfield and All Across Metro Detroit

Outsourced IT Support

& Phone Systems Services

From your cybersecurity to help desk, we’ve got you covered with tailored outsourced IT support to fit your needs. We are the trusted IT Services Company in Metro Detroit, to enhance productivity, protect your business, and achieve long-term success.

Outsourced IT Support & Phone Systems Services

for Southfield and All Across Metro Detroit

From your cybersecurity to help desk, we’ve got you covered with tailored outsourced IT support to fit your needs. Big Water Tech is the trusted IT Services Company in Metro Detroit, to enhance productivity, protect your business, and achieve long-term success.

Your Neighborhood Technology Success partner

Tress Saunders
Client Success Coordinator

Jennifer Shubow
Senior Sales Executive

Beverly Ames
Carrier Services Manager

Lisa Sariol
Manager of Operations

Robert Shubow
President

John Lowery
CEO

Marc Landau
IT Director

Bill Hickey
Client Services Manager

Glen Adams
Project Coordinator

Why Businesses Choose Big Water Tech

Comprehensive IT Solutions

Big Water Technologies offers tailored outsourced IT support solutions covering managed services, phone systems, cybersecurity, cloud services, and more.

Security and Compliance Experts

You can rest assured knowing we're security and compliance experts with the ability to protect your network while ensuring your environment exceeds regulatory requirements.

Exceptional Customer Service

Our team has been in the industry since the 1970s - allowing us to offer you informed, strategic insight while maintaining a high level of customer service.

Commitment to Client Success

You're far too busy to worry about technology. That's why your success is our success. We make IT work for you - so you can drive growth.

Client Success Stories

We currently use Big Water for our managed phone service and they are great! We have had issue with managed phone service providers in the past but Jenn is super responsive when we have an issue or need a new line added or removed. I would not hesitate to recommend Big Water for managed phone services, low voltage or other technology needs!

COLLEEN BUDDE

Franchise Owner at Office Evolution Troy

Is Your Technology Becoming Too Complex
For What It Needs To Be?

John Lowery
CEO, Big Water Tech

Big Water Tech is Here to Help Keep IT Simple with Bespoke IT Services.

At BigWater Technologies, safeguarding the integrity and security of your IT system is non-negotiable. We're dedicated to optimizing your technology to enhance efficiency and power.

Feel like you’ve been down this road before?

If you've felt burned by outsourced IT support providers in the past, rest assured, we prioritize fostering lasting client relationships over maximizing profits. Our focus is on maximizing the potential of your current IT infrastructure while keeping costs in check – possibly even reducing them.

Contact us at (248) 220-7714 to kick-start crucial IT discussions tailored to businesses like yours. Let's redefine your IT experience together.

Schedule an Appointment Today

As Your Technology Success Partner,
We're Here to Help You Drive Growth With:

Image

Simplified IT Management

BIGview offers proactive outsourced IT support and management of technology assets on a subscription basis.

Image

VoIP & Hybrid Phone Systems

Desktop & Mobile App, as well as Service Management with flexible VoIP service.

Image

Vendor Neutral Management

We provide a thorough needs assessment, available provider review, order management, issue management, and regular bill reviews.

Image

Comprehensive Equipment Support

We take care of your network security, switching, WiFi, servers, computers, video conferencing, and more.

Low voltage cabling, paging, and camera systems designed to fit the needs of your team.

Image

Ongoing Evaluation and Planning

Stay focused on the success of your company with regular proactive business reviews.

Want to see your Score? Get it in 30 seconds!

What Clients Say About Us

Excellent Response

They have been our IT support for a number of years and we have always had excellent response for any issues we were having. We currently going through the process of setting us up for more Cyber Security and eliminating the use of a server. They are bringing us up to date with all our computer needs. Their staff is very helpful.

John Gracey

Sharon Pare

Great Experience

We have been using Big Water for managed Services and Support for the past 5-7 years and have had great experience with everything from New Purchase, to Support, to their proactiveness to help us protect our systems. I highly recommend this company for your IT needs.

Kevin Truan

Alan Borsen

Highly Recommend Their Services

The folks of Big Water are super supportive and helpful. And they thoroughly seem to enjoy find their customers huge savings. Their accurate in their communication and prompt to follow through with any promises. Highly recommend their services.

John Gracey

Korienna Cox

Managing Your Security Has Never Been Simpler

Image

Discover Your Cyber Score

Start by assessing your Cyber Score to understand your business’s online security. This score provides clarity, replacing uncertainty with insight, so you know exactly where you stand and what needs improvement.

Image

Create Your Cyber Roadmap

Use your Cyber Score to develop a clear, actionable Cyber Roadmap. This plan highlights vulnerabilities and provides precise steps to strengthen your security, saving you time and resources. Schedule a meeting with Big Water Tech so we can help you create a clear, strategic path to cyber resilience.

Image

Enhance Your Security

Put your Roadmap into action with a step-by-step approach to stronger protection. Demonstrate your commitment to safeguarding customer data while equipping your IT team with a focused, cost-effective security strategy.

Want to see your Cybersecurity Score? Get it in 30 seconds!

The More You Know...

Our blog shares practical guidance, expert takes, and real-world lessons drawn from the front lines of IT services. Stay informed, stay protected, and make smarter decisions for your business.

5 outlines of people 1 computer screen

Why Shared Logins Are a HIPAA Violation: The Hidden Cost of "Saving Money" on Software Subscriptions

February 16, 20265 min read

Five people share one login. Which one accessed that patient record?

"It saves money on subscriptions."

I heard this last week from a medical practice owner. They had one login for their practice management system shared across the entire front office. Five people, one username, one password.

When something goes wrong — a record gets changed, data gets deleted, something gets accessed that shouldn't have been — who did it?

With a shared login, the answer is: "We don't know. Could have been anyone."

That's not a defensible answer for HIPAA, your insurance carrier, or a patient asking why their records were accessed.


What Are Shared Logins?

Shared logins occur when multiple employees use the same username and password to access a software system. Instead of unique credentials, everyone logs in with a single "office" account.

Medical practices commonly share logins for practice management systems, EHR/EMR platforms, billing software, and cloud storage — usually to avoid per-user license fees or for convenience.


Are Shared Logins a HIPAA Violation?

Yes. Shared logins violate the HIPAA Security Rule.

The HIPAA Security Rule requires Unique User Identification under §164.312(a)(2)(i), mandating covered entities "assign a unique name and/or number for identifying and tracking user identity."

When audit logs show "FrontDesk" accessed a patient record but five people use that account, you cannot comply with this requirement.

What Are the Penalties for HIPAA Access Control Violations?

Tier Description Penalty Range

Tier 1 Lack of knowledge $100 - $50,000 per violation

Tier 2 Reasonable cause $1,000 - $50,000 per violation

Tier 3 Willful neglect (corrected) $10,000 - $50,000 per violation

Tier 4 Willful neglect (not corrected) $50,000+ per violation

Annual maximums reach $1.5 million per violation category. "We were saving money on licenses" isn't a mitigating factor.


How Do Shared Logins Affect Cyber Insurance Claims?

Shared logins can result in denied claims and policy cancellations.

What Do Cyber Insurance Applications Ask About User Access?

  • "Do you have unique user accounts for all employees?"

  • "Do you maintain audit logs of user access?"

  • "Can you identify which user performed specific actions?"

Why Do Carriers Deny Claims Related to Shared Logins?

If you answer "yes" but share logins: You've made a material misrepresentation. Carriers may deny claims when they discover shared logins during investigation.

If you answer "no" honestly: Expect higher premiums, coverage exclusions, or denial.

When investigating incidents, carriers ask: "Who accessed the compromised account?" If your answer is "We don't know — five people use that login," you've demonstrated lack of basic controls and potential misrepresentation.


What Are the Security Risks of Shared Logins?

How Do Shared Logins Prevent Accountability?

Unauthorized Access: A staff member looks up records of a neighbor or ex-spouse. With unique logins, you identify who did it. With shared logins, you can't prove anything.

Departing Employees: Someone leaves on bad terms and accesses records they shouldn't. With unique logins, you revoke their access and audit activity. With shared logins, you change everyone's password and can't determine what they accessed.

External Breaches: Attackers compromise credentials through phishing. With unique logins and MFA, abnormal behavior triggers alerts. With shared logins, there's no baseline — five people use the account differently.

Why Can't You Detect Breaches With Shared Logins?

Security monitoring relies on baseline behavior patterns. When multiple people share one account, login times vary unpredictably, access patterns have no consistency, and distinguishing normal from abnormal activity becomes impossible.


How Much Do Shared Logins Really Cost?

The "Savings"

  • 5 users × $50/month = $250/month avoided

  • Annual "savings" = $3,000

The Potential Costs

Risk Potential Cost HIPAA fine (per violation) $100 - $50,000

HIPAA fine (annual max) Up to $1.5 million

Denied insurance claim $50,000 - $500,000+

Patient lawsuit $10,000 - $250,000+

Breach remediation $5,000 - $50,000+

The real math: You're betting $3,000 against six-figure losses.


What Compliance Frameworks Require Unique User Identification?

Framework Requirement

HIPAA Security Rule §164.312(a)(2)(i) Unique User Identification

CIS Controls v8.1 Control 5: Account Management

NIST CSF 2.0 PR.AC -1: Identities and credentials managed

PCI DSS 4.0 Requirement 8: Unique ID for each person

SOC 2 CC6.1: Logical access with unique identification

Every major framework requires identifying who did what, and when.


How Do You Eliminate Shared Logins?

Step 1: Audit Your Systems

Inventory every system containing sensitive data. Document how many accounts exist versus how many people use the system. Fewer accounts than users means shared logins.

Step 2: Create Individual Accounts

Work with vendors to set up unique accounts for every user. Ask about per-user pricing and audit logging capabilities. Budget for licenses — this is compliance, not optional.

Step 3: Enable Audit Logging

Enable logging on all systems with sensitive data. Capture who logged in, when, what they accessed, and changes made. HIPAA requires minimum 6-year retention.

Step 4: Add Multi-Factor Authentication

Enable MFA on EHR/EMR, practice management, email, cloud storage, and remote access. MFA ties authentication to something the individual has, making sharing harder.

Step 5: Document Policies

Create written policies prohibiting shared accounts. Include processes for account requests, access removal, and audit procedures. HIPAA requires written policies.

Step 6: Review Regularly

Activity Frequency Remove departed employee access Within 24 hours Review user accounts Monthly Audit log review Monthly Full access audit Quarterly


Frequently Asked Questions

Can small practices share logins?

No. Practice size doesn't change HIPAA requirements. A two-person practice has the same obligations as a 200-person hospital.

What if our software doesn't support multiple users?

Replace it. Software that doesn't support individual accounts with audit logging doesn't meet basic compliance requirements.

Is sharing okay for non-clinical systems?

It depends. If the system contains PHI, PII, or financial data, you need individual accounts. When in doubt, use individual accounts.

What about temporary staff?

They need individual accounts too. Every person accessing sensitive data needs unique credentials, regardless of employment status.


The Bottom Line

"It saves money on subscriptions" is one of the most expensive decisions a practice can make.

The subscription fees you're avoiding are nothing compared to a HIPAA fine you can't fight, a denied insurance claim, or a patient lawsuit you can't defend.

Every user needs their own login. No exceptions.

Keep IT Simple. One person, one login.


If your practice uses shared logins and you're not sure where to start, that's exactly the conversation we have with Michigan practices every week. Happy to point you in the right direction.

#KeepITSimple#SmarterBusiness#BigWaterTech#HIPAA
John Lowery is the CEO of BigWater Technologies, where he leads with a passion for innovation and excellence in delivering advanced IT solutions. With over two decades of experience in the tech industry, John specializes in strategic planning, operational efficiency, and driving customer success.

John Lowery

John Lowery is the CEO of BigWater Technologies, where he leads with a passion for innovation and excellence in delivering advanced IT solutions. With over two decades of experience in the tech industry, John specializes in strategic planning, operational efficiency, and driving customer success.

Back to Blog

Our Services

Image

Simple IT Management & Support

BIGview offers proactive management of technology assets on a subscription basis. BIGview is a service based offering designed specifically for your organization's requirements.

Image

Hosted Voice

Desktop & Mobile App, SIP Firewall, and Service Management with flexible VoIP service. Powerful call control on a local business number you can access from anywhere.

Image

Disaster Recovery & Backup

An automated data backup and restore system providing powerful tools to protect your organization's data. It doesn’t require any human assistance beyond the initial installation.

Image

Managed Cloud Environment

Protecting your data is incredibly important. Our BIGcloud Server is highly secure, extremely reliable, easy to scale, and has simple and affordable pricing.

Image

Managed File Sharing

BIGshare Managed Cloud Sharing is a secure, HIPAA & PCI compliant solution. Our BIGshare comes standard with backup and DRaaS all with unlimited storage for one simple price.

Image

Managed Security

BIGprotect is a comprehensive fully-managed security solution. It provides a powerful way to protect your organization’s network .

Image

Voice & Data Protection

BIGguard is a protection plan for your voice and data communications equipment. It provides a powerful way to protect your organization’s voice and data investment.

Image

Security Assessment & Reporting

Elevate your security posture with our assessment and reporting solutions. Gain comprehensive insights into your organization's security landscape.

Take IT Off Your Plate...

Spend less time on IT problems and more time growing your business. Let’s get to know each other and determine how our partnership could grow. With us on your side, you can develop a strong barrier against cybercrime, stronger communication strategies, and a better technology plan for the future.

Call (248) 220-7714 today or fill out the form below to schedule your appointment. We’re ready to jumpstart your IT journey.