TL;DR: Healthcare leaders report that shared mobile devices save an average of $1.1 million annually and that 92% now see them as essential to care delivery, but 44% still lack a formal policy and 79% of staff share credentials, according to Imprivata research. The governance gap is no longer about device availability; it is about access control, accountability, and operational discipline.
At a glance
What this is: Imprivata's research shows that shared mobile devices have become clinically essential in healthcare, but policy gaps, credential sharing, and weak oversight are limiting their secure use.
Why it matters: IAM, IGA, and PAM teams need to treat shared clinical devices as governed access surfaces, because shared sessions and shared credentials change accountability and raise patient data exposure risk.
By the numbers:
- 92% of healthcare leaders now consider mobile devices essential to care delivery.
- 44% of organizations lack a formal policy to manage device allocation and usage.
- 79% of staff admit to sharing credentials when accessing shared-use devices.
- 87% of care teams still encounter issues accessing devices at the start of their shifts.
Context
Shared mobile devices are no longer a convenience layer in healthcare. They are part of the access pathway for clinical work, which means device governance now sits inside the identity and access problem, not beside it.
The article's core gap is familiar to identity teams: organisations can expand device availability faster than they can define who may use a shared session, how access is assigned, and what accountability exists when a device changes hands. In healthcare, that gap affects both workflow speed and patient data exposure.
This is a human IAM and governance story, but it also intersects with PAM-like control expectations because shared devices often become shared access points. Where policy, authentication, and session discipline are weak, mobility gains are offset by control loss.
Key questions
Q: What breaks when shared healthcare devices have no formal policy?
A: The access model breaks because device handoff becomes informal, sessions persist between users, and accountability for data access becomes unclear. In practice, that means clinicians can inherit access, signed-in states can outlive a shift, and the organisation cannot reliably prove who accessed what at a given moment.
Q: Why do shared credentials create more risk in healthcare than in many other sectors?
A: Shared credentials weaken attribution in environments where timing, responsibility, and patient safety all matter. In healthcare, staff hand off devices across shifts, contractors enter and leave quickly, and the same endpoint may touch sensitive records many times a day. That combination makes reuse and persistence especially dangerous because the identity trail becomes unreliable.
Q: How do organisations know whether shared-device governance is working?
A: They should look for short access times, low workaround behaviour, clean audit trails, and consistent session resets at handoff. If staff are bypassing controls to keep care moving, governance is failing even if the devices are technically secure. Clinician satisfaction is also a useful signal because low usability often predicts policy drift.
Q: What should hospitals do first when shared mobile devices are essential but control is weak?
A: Start by defining ownership for allocation, sign-in state, and handoff responsibility. Once those responsibilities are explicit, organisations can enforce session cleanup, reduce credential sharing, and stop treating shared devices as unmanaged conveniences.
Technical breakdown
Why shared clinical devices break traditional login assumptions
Shared devices collapse the assumption that one user owns one endpoint for the duration of a session. In a clinical setting, the device is a temporary access surface, and the identity layer must distinguish between device availability, user assignment, and active session state. If the device remains signed in, the next user inherits context they should not see. That is not a hardware problem alone. It is an access governance problem that requires clear session boundaries, rapid re-authentication, and explicit offboarding of the prior user state.
Practical implication: treat shared-device handoff as an identity event, not a device checkout task.
Why usernames and passwords are a poor fit for shift-based access
Usernames and passwords work poorly when access is frequent, time-pressured, and shared across shifts. They encourage reuse, credential sharing, and stale sessions, especially when clinicians need fast access at the point of care. The article shows exactly that pattern, with 26% still relying on usernames and passwords and 79% of staff sharing credentials. The technical issue is not just weak authentication strength. It is that static credentials do not express assignment, role change, or session termination cleanly in a high-turnover environment.
Practical implication: move shared-device access toward stronger authentication that can support fast re-entry without credential reuse.
How policy enforcement and tracking determine whether shared access is governable
Shared device governance fails when allocation, sign-in state, and inventory tracking are managed in separate systems or by manual workarounds. The report points to sign-out sheets, spreadsheets, and missing devices as symptoms of that fragmentation. Once device state and identity state drift apart, it becomes difficult to know who was responsible for a given access event or whether a device remained exposed after handoff. The control problem is not just visibility. It is whether access state can be enforced and audited across the full use cycle.
Practical implication: align allocation policy, session state, and inventory tracking so handoff records are auditable.
Breaches seen in the wild
- iOS apps leaking hard-coded secrets: Cybernews found 71% of 156,080 iOS apps leak hard-coded secrets, with open cloud storage and Firebase databases exposing user data.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Shared mobile device governance has become an identity control problem, not a device management problem. The article makes clear that clinical mobility is now operationally essential, but that does not reduce the need for governance. When a device is shared, access ownership, session state, and accountability must be explicit or the control plane collapses into convenience.
Credential sharing on shared devices is a policy failure with direct privacy consequences. The fact that 79% of staff share credentials shows that the organisation is tolerating an access model that cannot reliably attribute actions to an individual user. In healthcare, that weakens auditability and increases the chance that sensitive data is exposed outside intended care workflows.
Formal use policy is the named concept this article exposes: shared-use access without lifecycle rules. A shared device strategy can save money and improve care, but only when allocation, sign-in, and responsibility are governed as a lifecycle. Without that, organisations get mobility gains with unmanaged access drift, which is exactly the trade-off this report surfaces.
Shared-device environments demand human IAM discipline even when the endpoint is the focal point. This is not a specialised mobile-management issue alone. It is a case where access control, recertification, and operational ownership all have to align around the shift-based reality of care delivery, or the identity layer becomes invisible to the workflow.
The market signal is clear: adoption has outrun governance maturity. Healthcare leaders now treat shared mobile devices as essential, but the control stack has not caught up. For practitioners, that means the next maturity step is not more device rollout, but stronger rules for access assignment, session handling, and accountability.
What this signals
Shared clinical devices need governance at the point of handoff. The main failure mode is not that the device exists, but that the access state survives too long between users. Identity teams should focus on how sessions are ended, re-issued, and audited in shift-based workflows.
Formal use policy is the control that makes mobility governable. Without it, allocation decisions, sign-in behaviour, and accountability drift apart. That is why device rollout alone does not close the risk gap in clinical environments.
Healthcare mobility programmes should be measured by access discipline, not device count. The meaningful signals are credential sharing, signed-in devices, missing-device rates, and whether clinicians still need unsupported workarounds like personal phones.
For practitioners
- Define a formal shared-device use policy Specify who may use a shared device, how access is assigned, when sessions must end, and who owns exceptions across shifts and departments.
- Replace shared passwords with accountable access flows Use individual authentication for shared clinical devices so actions remain attributable even when the device is reused by multiple staff members.
- Enforce session cleanup at handoff Require sign-out, lock, or equivalent session termination before a device changes users, and audit for devices left signed in.
- Inventory shared devices as governed access points Track missing devices, allocation status, and handoff timing together so identity and endpoint records can be reconciled during reviews.
- Reduce reliance on BYOD workarounds Address device availability at shift start so clinicians do not bypass institutional controls with personal phones or ungoverned access paths.
Key takeaways
- Shared mobile devices have become operationally essential in healthcare, but the governance model has not matured at the same pace.
- The biggest control gap is not device availability. It is policy, attribution, and session discipline across shared clinical workflows.
- Hospitals should treat shared-device handoff as an access-control event and build formal accountability into every shift change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | Shared clinical devices rely on authentication patterns that avoid credential reuse and shared logins. |
| Recommendation — Apply SP 800-63B to reduce shared credential use and strengthen re-authentication at device handoff. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about who can access shared devices and under what conditions. |
| Recommendation — Use PR.AA-05 to define and enforce access rules for shared clinical devices and shift-based users. | ||
| CIS Controls v8 | CIS-5 — Account Management | Shared device workflows depend on accurate account handling and removal of shared credential practices. |
| Recommendation — Apply CIS-5 to eliminate shared account use and keep device access attributable to named users. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access Control | The governance gap is an access control problem applied to shared clinical devices. |
| Recommendation — Implement A.5.15 to define access rules for shared devices and make handoff behaviour auditable. | ||
Key terms
- Shared Device Governance: The policy and control structure that defines who may use a shared endpoint, how access is assigned, and how accountability is preserved between users. In healthcare, it must account for shift changes, fast handoffs, and auditability across care workflows.
- Session Handoff Control: Session handoff control is the governance that ensures one user’s access does not silently continue into another user’s shift or task. It is especially important on shared devices because the risk is not just initial authentication, but who retains control after the operational context changes.
- Credential Sharing Workflow: A governed process for transferring or using a shared credential without losing ownership, visibility, or accountability. In practice, it should define who approved the sharing, how it is logged, and how the credential is recovered or replaced later.
- Shift-Based Access: An access pattern where different users need the same device or system at different times across a workday. In healthcare, the control challenge is to support speed without allowing persistent sessions, shared credentials, or unclear ownership.
Deepen your knowledge
NHI governance, human identity, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org