TL;DR: Healthcare leaders say passwordless access is mission-critical, with 85% rating it very important or mission-critical, but only 7% are fully passwordless and 59% still depend heavily on passwords, according to Imprivata. The gap is not a technology slogan problem, but a sequencing problem: consolidation, identity proofing, and adaptive controls have to land without breaking clinical workflows.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “Bridging the passwordless gap: A practical roadmap for healthcare IT”.
By the numbers:
- 85% of respondents said passwordless access is very important or mission-critical to the future of healthcare IT.
- only 7% report being fully passwordless today
- 59% still rely heavily on passwords
Key questions
Q: How should healthcare teams implement passwordless access without weakening security?
A: Healthcare teams should pair passwordless access with identity verification, credential governance, and explicit device policy.
Q: Why does passwordless adoption stall even when leaders support it?
A: Adoption stalls when integration, compliance, and clinical training are not treated as programme design constraints.
Q: How can security teams tell whether passwordless is actually safer?
A: Look for consistency, not just adoption.
Practitioner guidance
- Consolidate authenticators and identity proofing Inventory where passwords remain mandatory, where they are optional, and which vendors support shared workstation, remote access, self-service reset, and proofing under one policy model.
- Modernise recovery before broad rollout Replace knowledge-based password reset with verified self-service recovery so account recovery does not become the weakest path into clinical systems.
- Prioritise shared workstation workflows Map passwordless to badge tap, biometric confirmation, and session-aware access on shared devices before extending it to less constrained user journeys.
Bottom line: Healthcare passwordless programmes stall when identity proofing, recovery, and authentication policies are fragmented across too many tools.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless healthcare access is really an identity sequencing problem, not an authenticator problem. The article shows that leaders understand the destination, but fragmented vendors, recovery paths, and clinical workflow dependencies make the route difficult. The programme fails when teams treat password removal as the control objective instead of the outcome of identity consolidation, proofing, and adaptive policy. Practitioners should treat passwordless as a staged governance model, not a single deployment decision.
A few things that frame the scale:
- 60% of healthcare organisations do not assess a vendor's security before signing a contract that grants access to protected health information, according to Ponemon Institute's 2023 Third-Party Risk in Healthcare report.
A question worth separating out:
A: Passwordless authentication changes how users prove identity, using methods such as passkeys, biometrics, or hardware keys instead of passwords. Adaptive, risk-based authentication changes how much assurance is required based on context, such as device trust, location, or transaction value. In insurance, the two are often complementary because one improves the login method while the other tunes step-up checks.
👉 Read our full editorial: Healthcare passwordless access is mission-critical but still lagging