Start by mapping where clinicians encounter repeated authentication, inconsistent permissions, or workflow breaks, then redesign the identity journey so those steps are removed rather than compensated for later. The aim is not weaker control. It is consistent access that still enforces assurance while supporting care delivery.
Remove friction at the points that create it, not after the fact
Reducing access friction in NHS environments starts with identifying the repeat pain points clinicians actually feel, then removing unnecessary steps from the identity journey. Repeated login prompts, inconsistent permissioning and workflow breaks usually signal that access is being stitched on around care processes rather than designed into them. The security goal is to make the secure path the easiest path.
That means treating access as part of clinical workflow design, not just a back-office control. If staff have to re-authenticate because systems do not share a trust pattern, or because permissions vary by application and setting, they will work around the controls. Good design reduces the number of times a clinician has to prove who they are while preserving strong assurance at the right decision points.
Where security and usability can be aligned
The most effective improvements usually come from consistency: single sign-on where it genuinely reduces re-entry, coherent permission models across similar systems, and step-up authentication only when the action is sensitive enough to justify it. For remote and distributed care, Remote Access Identity Guide is a useful companion because it shows how MFA, ZTNA and device posture checks can reduce friction without weakening the assurance boundary.
Access friction also falls when organisations stop relying on exceptions as a normal operating model. Temporary workarounds, dormant remote access paths and duplicated accounts all add overhead for users and risk for security teams. In practice, consistent access outcomes depend on getting identity lifecycle, role design and access policy aligned so the user sees one predictable path instead of a different rule set in every application.
What NHS teams should standardise first
The first standardisation target is the set of actions clinicians do repeatedly and under time pressure. High-frequency tasks should have the fewest interruptions, while higher-risk actions should trigger stronger checks. That usually means aligning authentication strength with clinical risk and eliminating redundant permission prompts where the user and device context are already known.
A practical way to do this is to separate the question of “who can do it” from “how often must they prove it”. If an access decision is repeated every few minutes because systems are poorly integrated, the burden belongs in design, not in user endurance. Where a control is needed, it should be tied to the sensitivity of the action, not inserted as a generic obstacle across the whole workflow.
Risk and Threat Considerations
Friction can become a security weakness when users are forced to choose between delay and care delivery. In those conditions, people reuse sessions, share accounts, bypass remote controls or route around approvals, which creates a larger attack surface than the control was meant to reduce.
Failure mechanism: Inconsistent authentication and fragmented permissions encourage workarounds, and those workarounds often remove the very assurance checks the organisation depends on.
Impact: Attackers benefit from the same weak spots as legitimate users, especially where shared credentials, stale remote access or overbroad permissions let them move faster than defenders can detect.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Clinician access friction is driven by authentication frequency and assurance design. |
| AC-2 — Account Management | Consistent access depends on provisioning, role assignment and timely revocation across systems. | |
| AC-6 — Least Privilege | Least privilege lets teams remove unnecessary prompts while preserving action-level control. | |
| Recommendation — Consolidate organizational authentication so clinicians use fewer repeated login events. Standardize account lifecycle rules so permissions follow role changes without manual rework. Scope access to the minimum needed so strong checks remain tied to higher-risk actions. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account management directly addresses duplicated accounts, dormant access and access consistency. |
| Recommendation — Rationalize account management so duplicate or dormant access paths do not create friction. | ||
Practitioner Guidance
What to prioritise: Start with the most common clinician journeys and remove avoidable re-authentication, duplicate approvals and application-specific permission drift before adding new controls elsewhere. The biggest friction reduction usually comes from fixing the top few workflows, not from broad policy changes.
What to verify: Confirm that each access path still has a clear assurance level, a named owner and a revocation route. If you cannot explain why a control exists at a specific point in the journey, it is probably a candidate for redesign rather than retention.
Decision rule: If a control interrupts routine care but does not materially change the risk of the action, simplify it. If the action changes patient safety, confidentiality or the blast radius of compromise, keep stronger assurance even if it adds a step.
Practitioner takeaway: The right balance is not fewer controls, it is fewer unnecessary control events. When security is embedded in the workflow, staff experience less friction and the organisation gets better assurance because the control path is more likely to be followed.
Related resources from NHI Mgmt Group
- How should organisations reduce access friction for frontline workers without weakening security?
- How can security teams reduce friction without weakening privileged access controls?
- How should hospitals reduce password friction without weakening access security?
- How should healthcare teams reduce EHR access friction without weakening security?