Join our Newsletter — 33% off our NHI Course

What happens when EPCS is deployed without matching the authentication method to the care setting?

The result is usually poor adoption rather than a purely technical failure. High-volume areas need fast, repeatable authentication, while remote prescribing needs a method that works outside the hospital. If the chosen factor does not match the context, clinicians lose time, use becomes inconsistent, and the organisation risks undermining the entire EPCS effort. The control must fit the workflow to hold up operationally.

Why the authentication method has to match the care setting

EPCS succeeds when the factor fits the actual prescribing workflow, not when it simply satisfies a policy checkbox. In a busy inpatient or ambulatory setting, every extra step competes with patient flow; in remote prescribing, the method has to work when the clinician is away from hospital infrastructure. The practical question is whether the method supports safe prescribing without becoming the bottleneck.

That is why methods that are acceptable in one setting can fail in another. A factor that depends on shared devices, unstable connectivity, or repeated user actions may be tolerable at a desk but unworkable during clinical rounds, home visits, or telehealth. The control is part of the work process, so context determines whether it is usable enough to be adopted consistently.

When the match is right, authentication becomes a routine part of prescribing rather than an exception that people work around. When the match is wrong, clinicians either slow down to comply, find ad hoc shortcuts, or avoid using the function altogether. That is why EPCS design is as much an operational fit problem as it is an assurance problem.

What poor fit looks like in practice

The failure mode is usually friction, inconsistency, and workaround behaviour rather than a sudden outage. If a factor takes too long, is hard to repeat, or depends on conditions that are not present in the care setting, adoption drops and the organisation loses the benefit of the control. The prescribing workflow then becomes uneven across teams, locations, or shifts.

In high-volume environments, the wrong method creates delay at the exact point where repeatability matters most. In remote or distributed care, a method that assumes local device access or local support can leave prescribers unable to complete legitimate work. That often pushes users toward exceptions, shared accounts, delayed prescribing, or manual intervention, each of which weakens both control and trust in the process.

The key signal is not only whether the authentication is secure, but whether it can be completed reliably in the moments it is needed. If clinicians have to pause patient care, search for a workaround, or ask someone else to complete the step, the deployment is already misaligned with the care setting. For background on how healthcare access patterns and prescribing workflows interact, see NHIMG’s Healthcare Identity Security Guide and the Workforce Identity Security Guide.

How to judge whether the control is operationally fit

The best test is to evaluate the factor against the real prescribing context, not against a generic security preference. A method that works for high-throughput inpatient prescribing may not be suitable for remote prescribing, and a method that is easy on managed workstations may fail on mobile or off-site use. The right choice is the one clinicians can complete consistently without losing clinical time or creating unsafe delay.

NHIMG’s MFA Guide is useful here because it frames factor choice as an adoption and bypass problem, not just a configuration problem. For clinicians, the same principle applies: if the method is too brittle, too slow, or too location-dependent, users will avoid it or route around it. The control has to be repeatable under pressure.

For remote or distributed prescribing, the decision rule should be simple: if the method cannot be completed securely outside the hospital, it is not ready for that workflow. If the organisation expects a factor to work in telehealth, home-based care, or after-hours prescribing, it must be tested in those conditions before rollout. The right outcome is not just successful authentication, but successful authentication at the point of care.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines EPCS authentication should fit the required assurance level and authenticators for the prescribing context.
Recommendation — Map the prescribing workflow to the right assurance level and authenticator profile for that care setting.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management EPCS depends on authenticator lifecycle choices that work reliably in the target clinical workflow.
IA-2 — Identification and Authentication (Organizational Users) Clinicians are organizational users whose authentication must support safe, repeatable prescribing.
Recommendation — Select and manage authenticators so clinicians can complete EPCS without brittle or exception-driven processes. Implement clinician authentication that is dependable in the real prescribing environment.
ISO/IEC 27001:2022 A.5.15 — Access control EPCS requires access controls that align with operational prescribing workflows.
Recommendation — Align access control design with the actual care setting before deployment.
OWASP ASVS V6 — Authentication The problem is an authentication design fit issue, which ASVS treats as a core verification concern.
Recommendation — Verify authentication usability and robustness in the deployment context before release.

Practitioner Guidance

What to verify: Test the authentication method against the care setting that will use it most, including peak-load clinical periods and off-site prescribing. A method that passes in a pilot but fails during actual workflows is not operationally fit.

Decision rule: If clinicians need repeated exceptions, manual resets, or support desk intervention to prescribe, treat that as a deployment mismatch rather than a user-training issue. The control design needs revision before scale-up.

Common mistake: Selecting a factor because it is strong in the abstract, then assuming the workflow will absorb the friction. In EPCS, usability is part of security because unreliable authentication drives avoidance and workarounds.

Practitioner takeaway: The right authentication method is the one that preserves both assurance and clinical throughput, because a control that cannot be used reliably in the care setting will not be used consistently enough to protect the process.