Join our Newsletter — 33% off our NHI Course

Clinical MFA on shared workstations: what actually makes it usable?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Hospital login design determines whether strong authentication is used or bypassed, with shared workstations, slow sign-ins and session handoffs driving workarounds that break auditability and patient-record integrity, according to Crayonic research. The decisive control is not just MFA policy, but a ward-friendly login that takes seconds and follows clinicians between devices.

Editorial analysis by NHI Mgmt Group, based on content published by Crayonic: “From 105 seconds to 10: fixing the shared-workstation login in hospitals”.

By the numbers:

  • Single sign-on cut ward login time from 1 minute 45 seconds to 10 seconds at Alder Hey Hospital in Liverpool.

Key questions

Q: What breaks when MFA is too slow for clinical workstations?

A: Clinicians start bypassing the control with shared passwords, lingering sessions, taped credentials or informal handoffs.

Q: Why do hospital access controls need exceptions for emergency care?

A: Clinical environments include urgent access scenarios where a rigid login flow can delay care.

Q: How can security teams tell if ward authentication is actually working?

A: Look at login time, session reuse, shared-account behaviour and whether clinicians stay inside the approved path during busy shifts.

Practitioner guidance

  • Design for seconds, not minutes Rework ward authentication so routine sign-in is fast enough that clinicians do not need to improvise around it.
  • Separate shift-start assurance from day-to-day re-entry Use a stronger check at the start of a shift, then allow low-friction re-authentication for movement between workstations.
  • Eliminate shared ward accounts and informal session handoffs Make every chart action attributable to one person by removing ward accounts, taped passwords and colleague-to-colleague session passing.

Bottom line: Hospital login design directly shapes whether clinicians stay inside governed authentication paths or create their own.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Ward access is an identity governance problem, not a login preference. The article shows that clinicians will bypass controls that add minutes to a workflow measured in seconds. That means the real control boundary is usability at point of care, because policy without operational fit simply displaces risk into shared passwords and unmanaged session reuse. Practitioners should treat clinical authentication as a workflow control with governance consequences, not a standalone security feature.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What is the difference between a usable clinical login and a secure one?

A: A secure clinical login is one that staff can complete quickly enough to use under pressure, while still preserving individual accountability. If the design adds minutes, users will bypass it; if it takes seconds and follows the clinician, it can be both secure and operationally realistic.

👉 Read our full editorial: Ward login design is the real control in clinical MFA adoption



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.