Common signs include high drop-off during registration, repeated retries at proofing steps, complaints about document capture, and abandoned account recovery flows. If users cannot complete verification without confusion or delay, the process is probably too rigid for the risk involved. Effective programmes balance confidence in the identity proof with enough simplicity to keep legitimate users moving forward.
How to tell when identity proofing has become too hard for patients
The easiest signal is not a policy exception, it is friction showing up in user behaviour. When people repeatedly fail, abandon, or ask for help at the same step, the proofing flow is asking for more effort than the risk justifies. In healthcare, that matters because the process has to protect records without blocking legitimate access to care, benefits, or account recovery.
Burden usually appears first in the journey, not in a formal complaint. A process can feel “secure” on paper while still producing avoidable drop-off, support calls, and manual review because the steps are too long, too unclear, or too brittle for real-world users.
Which signs show the process is over-rotating on control
Look for patterns that repeat across users rather than one-off exceptions. High abandonment during registration or recovery, repeated retries on document capture, failure to complete liveness or upload steps, and requests to restart the flow are all signs that legitimate users are losing momentum. If the process needs multiple attempts to succeed for ordinary cases, it is probably too rigid.
Complaints are also a useful signal when they cluster around the same pain point, such as confusing instructions, camera or file-format problems, or long waits between steps. In healthcare, those complaints often indicate a mismatch between the assurance level being asked for and the practical stakes of the transaction.
Another warning sign is when the verification flow starts to depend on helpdesk intervention for normal users. If staff are routinely walking patients or members through the same proofing steps, the control may be functioning as a manual exception process rather than a scalable verification process. That usually means the experience is too complicated, not that users are unusually careless.
Where the balance usually breaks in healthcare verification
Healthcare verification becomes burdensome when the design treats every user as if they present the same fraud risk. A new member signing up for portal access, a patient recovering an account, and a high-risk case needing stronger proof are not the same problem. The process should scale the assurance request to the actual risk, not force the toughest path on everyone.
The practical issue is not whether stronger checks exist, it is whether they are proportionate. When a flow adds extra capture steps, repeated document re-entry, or unnecessary pauses without reducing a meaningful risk, it increases abandonment more than it improves trust. A well-designed process should let low-risk users complete verification quickly while reserving heavier checks for the cases that justify them.
For healthcare teams, the burden threshold is often visible in operational metrics: repeated retry rates, time-to-completion, escalation volume, and downstream account recovery failures. Those indicators matter because they show whether the process is still helping legitimate access or has become a gate that people cannot reliably get through.
Risk and Threat Considerations
Overly burdensome identity verification creates its own risk. Legitimate users may abandon onboarding or recovery, while support teams absorb more manual exceptions and may begin bypassing controls to keep service moving. That weakens both security and patient experience, especially when access to records, appointments, or portal messages is time-sensitive.
Failure mechanism: The flow becomes too strict, too slow, or too fragile for normal users, so they drop out, retry excessively, or rely on manual workarounds that reduce control consistency.
Impact: Higher abandonment, more support load, weaker assurance quality in practice, and greater pressure to approve exceptions that should have been handled by the standard process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, OWASP ASVS and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Covers user authentication assurance while balancing access friction for legitimate users. |
| IA-8 — Identification and Authentication (Non-Organizational Users) | Applies to patient and member identity proofing when external users must be verified. | |
| IA-5 — Authenticator Management | Relevant where repeated retries, recovery failures, and credential reset friction affect usability. | |
| Recommendation — Set authentication strength to the minimum needed for the transaction risk. Tune external-user proofing steps to the risk of the specific healthcare workflow. Reduce avoidable authenticator friction in recovery and reproofing paths. | ||
| OWASP ASVS | V6 — Authentication | Covers authentication flows where excessive steps can harm completion and usability. |
| V10 — OAuth and OIDC | Relevant when healthcare sign-in and identity federation flows add proofing friction. | |
| Recommendation — Validate that authentication requirements do not create unnecessary user drop-off. Check federation and sign-in flows for avoidable redirect and recovery complexity. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Directly addresses identity proofing and assurance trade-offs for external users. |
| Recommendation — Use assurance levels that fit the risk and keep the user journey achievable. | ||
Practitioner Guidance
What to verify: Review where users exit the flow, how often they retry the same step, and which step generates the most escalations. If the same stage is causing repeated failure for ordinary users, that is the point to simplify or redesign.
Decision rule: If a control measurably reduces completion for the legitimate population but does not clearly improve fraud resistance for the cases you are actually seeing, reduce friction first and reserve stronger checks for higher-risk transactions.
What good looks like: Most legitimate users complete verification in one pass, exceptions are rare and risk-based, and support is used for edge cases rather than as a normal part of the journey. At that point, the process is protecting the healthcare relationship instead of obstructing it.
Practitioner takeaway: In healthcare, a verification process is too burdensome when it starts converting ordinary users into exceptions, because the control is then degrading access without delivering proportionate security value.
Related resources from NHI Mgmt Group
- What are the signs that an identity verification process is collecting too much data?
- What are the signs that a digital identity verification programme is becoming too weak to prevent impersonation?
- What are the signs that a digital identity process is becoming too dependent on physical documents and manual checks?
- What are the signs that a manual identity verification process is too weak for modern screening?