Healthcare organisations should treat identity as part of the operating model, not a standalone IT project. The priority is to simplify access across organisations, reduce duplicate logons, and support staff moving between settings with consistent authentication. That means phased rollout, clear governance, and solutions that can scale from one department to a wider integrated care system without disrupting frontline work.
Reorganising digital identity across multiple care systems
When NHS structures change, identity design has to follow the operating boundary, not the org chart. The practical question is how to keep staff, contractors, and shared clinical support roles moving through services without multiplying logons, creating brittle local exceptions, or forcing every change through a one-off technical migration.
The right approach is to treat identity as shared service infrastructure for the care system, with local variations only where the clinical or legal model genuinely requires them. That usually means standardising authentication journeys, harmonising joiner-mover-leaver handling, and designing for federation or controlled trust between organisations rather than rebuilding identity stacks at every boundary.
Implementation should start with the identities and access paths that affect frontline work most often: clinicians crossing sites, temporary staff, shared support functions, and high-risk privileged access. In practice, this is where duplicated accounts, stale entitlements, and inconsistent authentication controls surface first, and where a phased approach is most likely to protect service continuity while reducing fragmentation.
What a multi-system identity model has to solve
A reorganised care landscape creates three linked problems. First, people need a consistent way to prove who they are across organisations, even if payroll, HR, and directory ownership remain split. Second, access must follow role and setting changes quickly enough to avoid delays in care. Third, the model has to scale without creating a new manual process every time a service moves into a different integrated care system.
That is why duplicate logons are more than an inconvenience. They usually signal duplicated identity records, overlapping account ownership, or policy drift between systems. If the same person is represented differently in different places, entitlement review, revocation, audit, and support all become harder, and the organisation loses confidence that access is current and appropriate.
Architecturally, the aim is to separate local organisational autonomy from the identity controls that benefit from consistency. Authentication and account lifecycle rules should be as uniform as possible, while authorisation can still reflect local clinical systems, job functions, and cross-boundary service arrangements.
How to roll out change without disrupting care delivery
A phased rollout is usually safer than a big-bang change because care systems cannot afford widespread login failures, especially where staff use multiple applications during a shift. Start with a limited population or pathway, prove that account linking, sign-in, support, and rollback all work, then expand once the operational model is stable.
Governance matters as much as technology. Organisations need a clear owner for identity decisions across the system, agreed rules for when a user should keep, merge, or lose access, and an escalation path for exceptions such as bank staff, locums, and cross-system roles. Without that, technical integration simply pushes confusion into service desks and local administrators.
A useful design principle is to minimise the number of places where identity data is edited. The more directories and local overrides that exist, the more likely it is that leavers stay active, movers retain excess access, or a change in one care setting fails to propagate to another.
Practical design choices that make integration sustainable
The strongest programmes standardise around a single identity journey for the user, even when the back-end remains federated. That means a common sign-in experience, consistent assurance expectations, and clear rules for when step-up authentication is required, while still allowing different systems to enforce their own authorisation logic where needed.
It also means planning for lifecycle management from the start. NHI Lifecycle Management Guide is a useful reference for the broader discipline of provisioning, rotation, offboarding, and visibility, while Identity Security Programme Guide is the better fit when the question is how to organise scope, governance, and roadmap across multiple teams.
For practitioners, this also aligns with the direction of eIDAS 2.0 , EU Digital Identity Framework and with NIST SP 800-63 Digital Identity Guidelines, both of which reinforce the value of consistent identity assurance and portable verification rather than isolated local sign-on models.
Risk and Threat Considerations
Identity reorganisation across care systems creates exposure when account ownership, authentication policy, and access revocation are not synchronised. The main risk is not just inconvenience, but uncontrolled overlap, where a person retains access in one system after role change, site transfer, or departure from another.
Failure mechanism: Duplicate identities, weak federation rules, and delayed deprovisioning allow stale or excessive access to persist across organisational boundaries, which increases the chance of inappropriate access, audit failure, or lateral movement through trusted accounts.
Impact: The result can be care-delivery disruption, governance gaps, and avoidable security exposure, especially where users work across multiple settings and support teams assume another organisation has already removed access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Identity assurance and portable verification are central to cross-system staff access. |
| Recommendation — Align authentication and assurance levels so users can move across systems without repeated identity fragmentation. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | The question is about governing digital identities through structural change across organisations. |
| A.5.18 — Access rights | The core challenge is keeping access consistent, current, and revocable as staff move between settings. | |
| Recommendation — Define a common identity ownership model for moves, joins, and leavers across the care system. Review and remove cross-boundary access promptly when roles, sites, or responsibilities change. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Workforce sign-in consistency across care systems depends on authenticated organizational users. |
| AC-2 — Account Management | Lifecycle handling of joiners, movers, and leavers is material to this multi-system identity change. | |
| Recommendation — Standardise workforce authentication so staff use one trusted sign-in path across participating organisations. Automate account provisioning and deprovisioning across systems to prevent stale access. | ||
Practitioner Guidance
What to prioritise: Start with the small set of identities whose failure would create the most operational friction, namely cross-boundary clinicians, support staff, and privileged administrators. If those flows work cleanly, the wider migration is much easier to govern.
What to verify: Before expanding rollout, verify that joiner, mover, and leaver events propagate correctly across every participating system, and that helpdesk, clinical operations, and identity owners agree on who can approve exceptions. The common mistake is to validate the login journey but not the account lifecycle.
Practitioner takeaway: In NHS reorganisation, the best identity model is the one that reduces variation for staff while preserving enough local control to match clinical reality, because that is what keeps access both usable and trustworthy.
Related resources from NHI Mgmt Group
- How should healthcare organisations implement remote identity proofing when patients need access across multiple providers?
- How should healthcare organisations implement data governance when critical reports are scattered across multiple systems?
- How should healthcare organisations implement identity controls across multiple clouds without creating new silos?
- How should organisations implement a digital identity trust framework across multiple service providers?