Saw a mid size clinic where the server was also the personal desktop of the boss - who also used the domain admin user as his main user account. His reasoning was that he needed to see "everything" his employees did and that none must come "above him" IT wise.
And before I forget it:The machine was in his office where he still was seeing patients and where often patients were left unattended - without him locking the machine.
Staat zahlt auch nicht - die tausenden Helfer der Hilfsorganisationen bzw. deren Organisationen haben quasi auch nix gekriegt.