It is almost never laziness
When three people use one account, somebody made a decision. Usually the decision was that the third seat cost more than it was worth, and the workaround was free.
That calculation is entirely rational at the desk, and it quietly removes the thing the hospital was buying.
What stops working
The audit trail stops naming a person. It still records that "reception1" cancelled the appointment, changed the price, or opened a chart, and "reception1" is three people, so the record answers nothing when it matters.
Permissions collapse to the most permissive person in the group. If one of the three needs to apply a discount, all three can. The careful role design underneath becomes decorative.
And clinical attribution becomes unreliable. A note has an author only if the account belongs to one person. If it does not, "who wrote this" has no answer, and that is a problem that surfaces at exactly the wrong moment.
The fix is a pricing decision
You can write policies about login sharing. Hospitals do, and they are ignored, because the incentive is pointing the other way.
The reliable fix is to remove the incentive: if an additional account costs nothing, nobody shares one. That is why Nirogix has unlimited users on every plan and prices on modules, branches and beds instead. It reads as a discount and it is really a security decision. We would rather have records that name a person than a per-seat line item.
A question worth asking any vendor
Not "do you have role-based access", because everyone says yes. Ask instead: "what does your pricing do to how many accounts we will actually create?"
The answer tells you whether the access control they demonstrated will survive contact with your budget.