Healthcare teams should treat shared workstations as an identity problem, not just an access problem. The practical starting point is to preserve user attribution while keeping logins fast enough for clinical workflows. That usually means strong authentication, rapid session switching, and single sign-on, so clinicians are not pushed toward unsafe credential sharing or broad generic access.
Why shared workstations change the Zero Trust design
Shared clinical workstations are not just a convenience problem, they change the trust boundary. zero trust still applies, but the implementation has to preserve who is acting at the keyboard, even when the device is shared across many staff members and sessions move quickly between them. That makes identity, session control, and workflow fit more important than device ownership alone.
The key design choice is to make access step up for the right moments, not force a full re-authentication for every interaction. In practice, healthcare organisations should combine strong authentication at entry, short-lived but usable sessions, and clear session handoff rules so the workstation remains fast enough for bedside use without turning into a shared, unaccountable terminal.
fast user switching works best when the system treats the next clinician as a new active identity, not as a continuation of the previous one. That means the workstation should lock the prior session state, rebind the clinical application to the incoming user, and avoid leaving cached data, open charts, or elevated privileges attached to the device after the handoff.
Controls that keep the workflow fast without losing attribution
Healthcare teams usually need three controls working together: single sign-on for speed, strong authentication for confidence, and rapid session switching for the bedside workflow. SSO reduces repeated prompts, but it should be paired with policy checks that confirm the clinician, the device state, and the current context before sensitive actions are allowed. A Zero Trust Identity Guide is useful here because it frames Zero Trust as an identity-centric model rather than a device-centric one.
Shared workstation design also needs an explicit account model. Generic logins, shared passwords, and “everyone uses the same charting account” practices break attribution and make access review meaningless. The better pattern is named user access with rapid re-authentication at the right control points, backed by role-based access and least privilege so each clinician gets only the functions needed for their current role. For broader governance of people, devices, and entitlements, IAM and IGA Basics is a good reference point.
Where clinical teams rely on roaming access, workstation design should also fit into the wider Zero Trust architecture, not sit outside it. That means verifying the user, checking the session, and enforcing policy per request rather than assuming that a logged-in device is permanently trusted. NIST SP 800-207 Zero Trust Architecture and NHIMG’s Zero Trust Identity Guide both support that approach.
What can go wrong if the handoff is sloppy
Fast user switching creates risk when the previous clinician’s session remains active in a way the next clinician can use without re-establishing identity. In a hospital, that can lead to charting errors, unauthorized record access, accidental ordering under the wrong name, and overbroad access that hides who actually performed an action. The danger is not only malicious misuse, but also everyday operational confusion that weakens auditability.
Failure mechanism: The workstation or application keeps the previous identity context alive, so the next user inherits an authenticated session, cached token, or open application state without a proper identity transition.
Impact: Clinicians lose clear attribution, shared devices become a path to unauthorized access, and the organisation may be unable to prove who viewed, changed, or ordered what in a clinical record.
For healthcare environments, that failure often becomes a governance problem as much as a security problem. If clinicians have to choose between speed and accountability, they will usually choose speed, which is why the control has to be built into the workflow rather than enforced as an after-the-fact policy reminder. The Healthcare Identity Security Guide is directly relevant because it addresses shared workstations, clinician access, and the realities of healthcare operations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | N/A — Zero Trust Architecture | Shared workstation Zero Trust depends on per-request verification and session boundary control. |
| Recommendation — Apply per-request policy checks and reauthenticate at key session transitions. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Clinician logins require named-user authentication on shared workstations. |
| AC-6 — Least Privilege | Shared clinical access should limit what each session can do at the workstation. | |
| Recommendation — Use named-user authentication for every clinician session and avoid shared accounts. Restrict each workstation session to the minimum clinical permissions needed. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged access rights | Shared clinical access must prevent broad standing rights on common workstations. |
| Recommendation — Limit standing privileges on shared clinical workstations and review them regularly. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Named access and session control are central to safe shared workstation use. |
| Recommendation — Manage access by named user and remove shared credentials from clinical workflows. | ||
Practitioner Guidance
What to prioritise: Make attribution the first design requirement. If a workstation cannot reliably show which clinician is active at the moment of access, the Zero Trust design is incomplete even if authentication is technically strong.
What to verify: Confirm that fast user switching actually clears the prior user’s session, cached credentials, and application context before the next user proceeds. Test the full handoff path in the EHR, not just at the Windows or device login screen.
Decision rule: If the workstation supports clinical interruption and handoff, use SSO plus rapid re-authentication with named accounts. If it cannot preserve attribution cleanly, treat that device as a higher-risk shared terminal and tighten the allowed actions accordingly.
What good looks like: A clinician can resume care quickly without seeing another user’s open session, and every meaningful action remains tied to a specific, current identity in the audit trail.
Practitioner takeaway: In healthcare, Zero Trust for shared workstations succeeds when the handoff is frictionless for clinicians but explicit for identity. Speed matters, but not at the cost of losing who did what, when, and under whose authority.
Related resources from NHI Mgmt Group
- What happens when clinicians use shared workstations without fast user switching?
- How should organisations implement zero-trust architecture when they still rely on legacy and non-containerised systems?
- How should organisations implement Zero Trust in enterprise IAM without weakening user productivity?
- Why do non-human identities complicate zero trust architecture?