A fictional story about a real IGA failure pattern.
Nobody pressed a wrong button.
That was the first thing the auditors noted.
The breach at Cascade Health Systems — 2.1 million patient records, fourteen months of undetected access — was the product not of a single mistake, but of accumulated silence. Of workflows that said approve when they should have said wait. Of a governance engine running faithfully on the wrong assumptions.
It began, as most IGA failures do, with a role.
In March 2025, Cascade’s clinical informatics team onboarded a new vendor, MediAnalytics Corp, to support population health reporting. The integration required read access to the enterprise data warehouse — scoped, technically reasonable. The IGA team provisioned it under a new role. The role was marked business-owned, with quarterly certifications assigned to the Director of Clinical Informatics.
She was thorough, well-meaning, and twelve meetings behind at any given moment.
She received the first certification campaign in July. She opened the email. She saw forty-three items, each with a green checkmark pre-populated by the system — a feature the IGA team had enabled to “reduce reviewer fatigue.” She clicked Submit All in under ninety seconds.
The system recorded it as a successful certification. In the audit trail, it looked immaculate.
What the pre-population hid: six of the forty-three items were not MediAnalytics accounts. They belonged to a billing vendor that had been offboarded eight months earlier. The accounts had survived. Someone had folded them into the active vendor role during a cleanup exercise. No one flagged the orphan. The certifier was never told.
Two of those accounts still had working credentials — silently rotated and retained by the defunct vendor’s cloud environment before offboarding was finalized. A misconfigured script had missed two service principals.
Now, certified quarterly, they were governed access.
For fourteen months, two credential sets belonging to a vendor that no longer existed quietly queried Cascade’s enterprise warehouse — patient demographics, diagnosis codes, claim history, risk scores. The queries were small, well-formed, indistinguishable from legitimate analytics traffic. The exfiltration happened at 2am on Sundays. The SIEM had a rule to suppress low-volume off-hours traffic from certified vendor roles, to reduce alert noise.
It was an auditor who found it. Not a tool. A human being named Marcus, reviewing access logs for a routine HIPAA readiness assessment, who noticed a service account tied to a vendor that had been gone for over a year.
He contacted the certifier.
She said she had never heard of that vendor. She had assumed all forty-three items were MediAnalytics accounts.
“The governance said it was fine,” she told the investigation team. “It told me everything was fine.”
The CISO’s statement to the board contained one line that has stayed with me:
“We built a system that was very good at producing evidence of governance. We were less careful about whether governance had actually occurred.”
Cascade Health Systems is fictional. The failure pattern is not.
IGA doesn’t fail loudly. It fails quietly, compliantly, with a green checkmark and a timestamp.
The lesson is not that certification campaigns are useless. It is that access review only works when reviewers are given context, friction, and permission to say no. Rubber-stamped reviews do not reduce risk. They preserve it.
If you run IGA programs, own application access, or certify access reviews, ask one honest question:
When was the last time a reviewer pushed back on an item, questioned a role, or revoked access?
If the answer is “rarely” or “never,” you may not have governance.
You may have evidence of governance.
That distinction is worth a conversation.