Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

PBM authentication sprawl and account takeover risk for IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: PBMs are operating at the intersection of high-value member data, fragmented portals, and regulatory pressure, and Descope’s analysis argues that legacy authentication models no longer fit that environment. The real problem is not just password friction, but the governance gap created when multiple stakeholder types, integrations, and M&A all depend on inconsistent identity controls.

NHIMG editorial — based on content published by Descope: Auth and Identity Tips for Pharmacy Benefit Managers

Questions worth separating out

Q: How should PBMs reduce account takeover risk without making member access harder?

A: Use passwordless options, risk-based MFA, and consistent recovery flows so legitimate users can authenticate without repeated friction.

Q: Why do fragmented PBM portals create security and compliance problems?

A: Fragmented portals let authentication, logging, and role design drift apart, which makes it harder to enforce the same control standard across every user group.

Q: How can security teams govern shared or family access in healthcare portals?

A: They should replace informal password sharing with explicit delegated access tied to the actual relationship being represented.

Practitioner guidance

  • Consolidate identity policy across every portal Create one baseline for MFA, recovery, session controls, logging, and role assignment across member, pharmacy, employer, and broker portals.
  • Trace delegated access through healthcare integrations Document OAuth flows, token scope, consent handling, and revocation paths for ePA, SMART on FHIR, and EHR-connected workflows.
  • Separate family access from shared credentials Define explicit dependent and household access models so legitimate shared use does not rely on credential sharing.

What's in the full article

Descope's full article covers the implementation detail this post intentionally leaves for the source:

  • Passwordless and adaptive MFA patterns tailored to member, pharmacy, and partner access journeys.
  • Multi-tenant SSO and self-service onboarding details for employer and broker integrations.
  • Delegated admin and fine-grained authorization workflow design for operational teams.
  • SMART on FHIR and API authorization support for connected healthcare workflows.

👉 Read Descope's analysis of PBM authentication, access, and compliance challenges →

PBM authentication sprawl and account takeover risk for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

PBM identity is a mixed human IAM and lifecycle problem, not a login problem. The article correctly treats members, pharmacies, prescribers, employers, and brokers as distinct access populations with different risk profiles. That means the control challenge is lifecycle governance across multiple user classes, not a single authentication pattern. The implication is that PBMs need to govern identity relationships, entitlement scope, and offboarding consistency as one programme.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly remediation can move once identity exposure is discovered.

A question worth separating out:

Q: Which compliance concerns should identity teams expect in PBM environments?

A: HIPAA, state PBM licensing, and FTC transparency obligations all increase the need for audit-ready authentication and authorization records. Teams should be able to show who accessed what, under which role, and through which workflow. Good logs are not optional evidence, because regulators increasingly expect identity controls to be traceable.

👉 Read our full editorial: PBM identity and authentication gaps are raising fraud risk



   
ReplyQuote
Share: