Common warning signs include frequent password entry, slow access to virtual desktops or clinical apps, workarounds for repeated prompts, and clinicians spending measurable time on login tasks instead of patient care. If security controls regularly interrupt routine workflows, they are no longer operating as invisible protection and should be re-evaluated.
When access controls start getting in the way
The burden usually shows up first in the rhythm of clinical work, not in a policy document. If a nurse, physician, or technician has to stop, re-authenticate, wait for a slow session, or take an unsafe shortcut just to reach routine systems, the control design is no longer fitting the workflow. That is a usability signal, but it is also a security signal because frustrated users tend to route around controls instead of through them.
At that point, the right question is not whether access control exists, but whether it is aligned to clinical context, device context, and task frequency. Controls that are too rigid, too slow, or too chatty can create friction that accumulates across a shift and becomes measurable lost time.
Clinicians also reveal burden indirectly through coping behaviour, such as shared sign-ins, reusing sessions, leaving terminals unlocked, or delaying charting until later. Those workarounds are important because they often indicate that the control is being experienced as an obstacle rather than as a protective layer. In practice, the burden is real when the control changes behaviour in ways that reduce both care quality and control effectiveness.
Operational signs that the burden is becoming material
Look for repeated prompts that arrive inside ordinary care tasks, not just at shift start or after long inactivity. Slow virtual desktop logons, multi-step authentication loops, and access denials for systems that should be routine are all signs that the control path is too expensive for the frequency of use. When access overhead is high, clinicians start to associate security with delay, which makes compliance less reliable.
Another strong indicator is the growth of exception handling. If teams are asking for permanent bypasses, emergency access every day, or broad role assignments just to keep clinics moving, the control model is probably too coarse. In an environment like healthcare, that often means the access policy was designed around abstract user groups rather than around actual patient-care tasks and shift-based access patterns.
It is also worth separating occasional annoyance from systemic burden. A control can be inconvenient and still acceptable if it is rare, predictable, and easy to recover from. It becomes a burden when the interruption is frequent, when the recovery path is unclear, or when it affects multiple systems in sequence, such as EHR access, virtual desktop access, and application-level prompts all stacking on top of each other.
For access model refinement, compare the lived experience against clearer authorization patterns such as role-based, attribute-based, or relationship-based access. NHIMG’s Authorisation Models Guide is useful when the problem is not “too much security” but “the wrong access decision at the wrong granularity.” The same logic applies to broader IAM design, where IAM and IGA Basics helps distinguish access design issues from lifecycle and governance issues.
What burden means for security and care delivery
When access controls become burdensome, the immediate operational impact is lost time, but the deeper risk is control erosion. Staff may ask for wider standing access, reuse sessions, or rely on informal sharing to keep work moving. That weakens the very boundary the control was meant to enforce and can expand exposure across charts, medication workflows, and administrative functions.
The burden can also hide in plain sight because it often appears as efficiency workarounds rather than policy failures. A login flow that “mostly works” may still create enough friction that staff stop logging out properly, keep browsers open longer than they should, or avoid using protected tools altogether. In clinical settings, those compensating behaviours can be just as important as any technical defect because they alter the effective security posture.
Healthcare environments are particularly sensitive because access controls must protect data without interfering with time-critical care. NHIMG’s Healthcare Identity Security Guide is relevant here because clinician workflows, shared workstations, and regulated access patterns make friction visible very quickly. For privileged or break-glass scenarios, Privileged Access Management Guide helps distinguish legitimate emergency access from routine overuse of exceptions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Clinician login friction is an authentication design issue. |
| AC-2 — Account Management | Frequent prompts and exception use often reflect account design and lifecycle problems. | |
| AC-6 — Least Privilege | Burden often leads to overbroad access to avoid delays. | |
| Recommendation — Reduce unnecessary authentication steps while preserving assurance for clinician access. Tune account scopes and session rules to fit clinical roles and shifts. Right-size entitlements so routine clinical tasks need fewer exceptions. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The issue is excessive friction in day-to-day access enforcement. |
| Recommendation — Review access workflows and remove avoidable friction in high-use clinical paths. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control policy must support the workflow it protects. |
| Recommendation — Align access rules with actual clinical access needs and process frequency. | ||
Practitioner Guidance
What to prioritise: Focus first on the highest-frequency clinical journeys, such as chart review, medication administration, imaging, and desktop re-entry after brief inactivity. If those paths are slow or repetitive, they create the most cumulative burden.
What to verify: Confirm whether the pain comes from authentication, authorization, session timeout, virtual desktop latency, or application design. Different failure points need different fixes, and treating them all as “user resistance” usually delays the real remediation.
Common mistake: Teams often add more prompts or broader exceptions instead of simplifying the actual access journey. That can make the workflow feel safer while quietly increasing the chance of workarounds, standing access, and weak session hygiene.
What good looks like: Clinicians should be able to move through routine tasks with minimal interruption, while higher-risk actions still require stronger checks. The control should be visible in its protection, not in the amount of time it consumes.
Practitioner takeaway: If access controls regularly force clinicians to choose between speed and compliance, the design is misaligned and should be reworked before the workarounds become the real operating model.
Related resources from NHI Mgmt Group
- When should organizations review access controls?
- What are the signs that Kubernetes access controls are becoming too broad or too hard to manage?
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?