TL;DR: A peer-reviewed study across 55 hospitals in four nations found clinicians can lose millions of hours each year to repeated logins, with SSO/AM freeing 3.3 million hours and £54.1 million in value according to Imprivata and AHISP. Authentication is no longer just a security gate in healthcare, because login friction directly affects care delivery, compliance, and staff burnout.
At a glance
What this is: This is a healthcare identity and access analysis showing that repeated logins in hospitals consume millions of clinician hours and make single sign-on an operational security control.
Why it matters: It matters because IAM teams in healthcare have to treat authentication design as part of patient safety, staff productivity, and privacy compliance, not just user convenience.
By the numbers:
- The study covered 55 hospitals across four nations.
- The research says the value created reached £54.1 million, or $68.7 million.
Context
In hospital environments, authentication is not a side issue. Every additional EHR, lab portal, or prescribing system adds another login step, and that friction lands directly on clinicians who move quickly between patients, devices, and workflows.
The governance problem is familiar to identity teams: when access is fragmented across systems, users start working around controls rather than through them. In healthcare, that behaviour has direct implications for privacy mandates, auditability, and staff fatigue.
The article frames single sign-on and access management as a way to reduce the gap between security policy and clinical reality. That makes the discussion about identity operations, not just user experience.
Key questions
A: Healthcare teams should combine strong identity controls with a workflow designed around fast clinical access. Single sign on, badge based authentication, and session continuity can reduce repeated logins while preserving security. The goal is not to remove control, but to make authentication less disruptive so clinicians spend more time on patient care and less time recovering passwords or relaunching applications.
Q: Why does repeated authentication create risk in healthcare environments?
A: Repeated authentication creates risk because it increases cognitive load, slows care delivery, and encourages workarounds. In hospitals, that often shows up as shared sessions, delayed logout, or skipped security steps. Those behaviours weaken compliance and make access control less reliable. Friction becomes a governance problem when the control is too cumbersome to use consistently.
Q: What are the signs that access controls are failing in a hospital workflow?
A: Warning signs include shared mobile devices disappearing from cabinets, unsecured desktops left open with applications running, staff using personal email or personal accounts for hospital information, and clinicians depending on shared passwords. Another clear signal is when new hires or interns cannot get timely access and end up observing instead of working. These patterns show access is too slow, too complex, or too loosely governed.
Q: Should healthcare organisations prioritise single sign-on over adding more login controls?
A: They should prioritise reducing authentication friction before layering on more checkpoints, because more prompts rarely fix the underlying workflow mismatch. In clinical settings, a control that slows care can undermine both compliance and adoption. SSO becomes useful when it reduces repeated logins while preserving entitlement governance.
Technical breakdown
Why repeated hospital logins create identity friction
Healthcare authentication sprawl happens when each application maintains its own login boundary instead of participating in a shared session model. Clinicians then re-authenticate across EHRs, pharmacy tools, lab systems, and bedside devices, which increases cognitive load and raises the odds of insecure workarounds. In practice, this is an identity design problem: the system is asking people to bridge gaps that the architecture created. When workflows are time-pressured, friction becomes a governance failure as much as an operational nuisance.
Practical implication: consolidate authentication surfaces so clinicians do not have to manage separate credentials for every clinical system.
How single sign-on changes access control in clinical workflows
Single sign-on reduces repeated authentication by creating one trusted session that can be reused across authorised applications. That does not remove access control, but it changes where control is enforced: at session initiation and entitlement management rather than at every application handoff. In healthcare, that matters because clinicians need fast access without weakening privacy or traceability. SSO works best when paired with access management that still enforces role boundaries, device trust, and logging across the downstream systems.
Practical implication: pair SSO with role-based access and session logging so speed does not come at the cost of auditability.
Why screen-time fatigue becomes a security issue in hospitals
Screen-time fatigue appears when repeated authentication steps compete with care delivery and encourage bypass behaviour. A clinician who logs in and out dozens of times per shift is more likely to delay logout, share access patterns informally, or tolerate insecure shortcuts just to keep moving. That turns usability into a security control issue. The article's core point is that compliance improves when the access model fits the pace of clinical work, because policy is easier to follow when it does not constantly interrupt care.
Practical implication: design authentication flows around clinical tempo so security behaviour remains realistic under shift pressure.
NHI Mgmt Group analysis
Single sign-on in hospitals is now an identity governance control, not a convenience feature. The article shows that authentication friction has measurable operational cost in clinical environments, which means access design directly shapes staff behaviour. When clinicians spend time fighting logins, security policy competes with care delivery and often loses. The practical conclusion is that healthcare IAM has to be judged on whether it supports compliant work at shift speed.
Credential sprawl is the underlying problem, and SSO only becomes valuable when it reduces the number of boundaries clinicians must cross. A hospital can have strong policies on paper and still produce unsafe workarounds if every system demands a separate login. That is a governance failure because the control model is misaligned with the work model. The lesson for identity teams is that fragmented access architecture creates its own risk surface.
Clinical identity fatigue: repeated authentication demands create both burnout and control bypass pressure. The article links login burden to clinician morale, workflow disruption, and stronger pressure to skip security steps. That is the kind of signal identity programmes should treat as a design defect, not just a user complaint. In healthcare, a control that cannot survive the pace of care is not a durable control.
Authentication is becoming a clinical performance metric because the cost of delay now shows up in productivity, compliance, and trust. The study's value case shows that reducing login burden returns time at scale, but the strategic point is broader: identity infrastructure is part of the care pathway. This shifts IAM discussions from back-office support to clinical enablement, which is where healthcare security programmes need to operate.
Hospitals are proving that access management and patient safety are converging governance concerns. The article suggests that when access workflows are streamlined, staff can comply more consistently with privacy mandates and still move quickly enough to deliver care. That is a useful pattern for any regulated environment: if the control is hard to use, users will route around it. Identity leaders should treat usability as a compliance variable, not a separate issue.
What this signals
Clinical access design now sits inside the security programme. Healthcare teams should treat repeated logins, delayed logout, and fragmented authentication as governance signals, not isolated user complaints. When the access model does not fit the work model, compliance degrades because clinicians route around controls to keep care moving.
Single sign-on is only half the answer. The real programme question is whether session consolidation is paired with entitlement discipline, device trust, and audit logging that still hold up in regulated care environments. Without that layer, convenience can outpace governance.
Hospitals should measure friction as an operational risk indicator. If staff experience authentication as a barrier rather than a control, the organisation will usually see weaker policy adherence, more burnout, and less reliable privacy behaviour. The lesson is to govern access paths with the same seriousness as any other clinical infrastructure.
For practitioners
- Map login burden across clinical workflows Measure how many separate authentications clinicians complete per shift across EHRs, lab tools, prescribing systems, and shared workstations. Use that baseline to identify where access friction is driving unsafe workarounds.
- Consolidate high-frequency access into SSO Prioritise the systems clinicians touch most often and move those to a single session model first, while preserving downstream entitlement checks and logging.
- Align access policy to clinical tempo Review logout, re-authentication, and timeout settings against actual shift patterns so controls support privacy compliance without creating avoidable interruption.
- Monitor bypass behaviour as a control signal Treat delayed logout, shared workstations, and informal credential reuse as evidence that the current access design is too costly to use consistently.
Key takeaways
- Repeated logins in hospitals create both productivity loss and governance friction, which is why access design now affects care delivery as well as security.
- The study links SSO and access management with millions of clinician hours recovered and measurable financial value, showing that authentication architecture has operational consequences.
- Healthcare IAM teams should reduce login burden first and preserve control through downstream entitlements, logging, and policy discipline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on access design and entitlement handling across hospital workflows. |
| Recommendation — Apply PR.AA-05 to reduce repeated authentication while preserving authorised access boundaries. | ||
| NIST SP 800-63 | SP 800-63C — Federation | SSO is fundamentally a federation and session reuse problem in a clinical environment. |
| Recommendation — Use SP 800-63C to align hospital SSO design with federated trust and session governance. | ||
| CIS Controls v8 | CIS-5 — Account Management | The issue is credential and account sprawl across many clinical applications. |
| Recommendation — Use CIS-5 to rationalise account sprawl and reduce the number of logins clinicians must manage. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | Hospitals must still govern elevated access even when SSO reduces login friction. |
| Recommendation — Review privileged access paths so SSO does not obscure who can reach sensitive clinical functions. | ||
Key terms
- Single Sign On: Single Sign On is a login method that lets a user access multiple applications with one authenticated session. Technically, an identity provider issues a trusted authentication assertion or token after the user signs in, and connected services accept that proof instead of requiring separate passwords for each application.
- Access Management: Access Management is the set of controls that authenticate a user or workload and decide what it can reach at run time. It includes sign-in, session control, policy enforcement, and authorisation decisions, all of which become harder to manage when identities are non-human and highly automated.
- Authentication Friction: The delay, confusion, and support burden created when users cannot complete sign-in cleanly. In IAM programmes, friction is a governance signal because it drives resets, exceptions, and workarounds. If users routinely hit the recovery path, the authentication design is not yet operationally stable.
- Clinical Workflow: Clinical workflow is the sequence of tasks, decisions and system interactions used to deliver care. In identity programmes, it matters because access controls only work well when they reflect how staff actually move, collaborate and use applications in wards, clinics and specialist settings.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org