TL;DR: Healthcare IAM must balance clinician speed with stronger assurance, role precision, and Zero Trust-aligned access governance, as Imprivata says its expanded Enterprise Access Management platform adds facial recognition, high-assurance identity verification, and AI-powered behavioural analytics to help NHS organisations strengthen access controls, support audit evidence, and reduce dependence on shared credentials.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “Imprivata Introduces New Advanced Access Management and Passwordless Authentication Capabilities to Address Evolving NHS Cyber Security and Compliance Challenges”.
Key questions
Q: How should healthcare teams implement passwordless access without weakening security?
A: Healthcare teams should pair passwordless access with identity verification, credential governance, and explicit device policy.
Q: Why do passwordless controls still need role-aware authorisation in NHS environments?
A: Because authentication only answers who signed in, not what that person should be allowed to do once the session starts.
Q: What are the signs that behavioural analytics is not tuned for healthcare access patterns?
A: Common signs include excessive step-up prompts, false alerts during normal shift changes, and security teams ignoring the output because it does not match how clinicians actually work.
Practitioner guidance
- Review shared-device access flows Map how clinicians authenticate on ward and front-desk devices, then check whether the current flow proves user identity and session ownership well enough for audit and incident review.
- Tighten role and attribute rules Validate that access grants change with role, location, and task context rather than relying on broad standing entitlements that survive beyond the clinical use case.
- Add assurance evidence to DSPT submissions Capture authentication events, factor types, and access decisions in a form that supports assessment evidence instead of relying on policy statements alone.
Bottom line: Passwordless access changes how NHS organisations prove identity assurance, but it does not remove the need for authorisation and audit evidence.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless is changing the identity control set in healthcare, not simply replacing passwords. In NHS environments, the control question shifts from secret handling to assurance, device context, and audit evidence. That matters because clinicians need fast access, but governance teams still need proof that access was correctly established and attributed. The practitioner conclusion is that authentication design now has to be judged as part of the full access control chain, not as a standalone login experience.
A few things that frame the scale:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
A question worth separating out:
Q: What should teams do when shared clinical devices make access accountability hard to prove?
A: Treat the device and session as part of the identity event, not just the user credential. Stronger identity verification, detailed authentication logs, and role-bound access records help establish who used what, when, and under which entitlement.
👉 Read our full editorial: Passwordless NHS access management changes the identity control set