Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What breaks when online prescription workflows depend on…
Authentication, Authorisation & Trust

What breaks when online prescription workflows depend on passwords alone?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

When online prescription workflows depend on passwords alone, they fail to provide reliable positive identification of the prescriber. Shared credentials, stolen passwords, and weak account hygiene make it hard to prove who actually authorised the order. The result is higher exposure to prescription fraud, policy violations, and avoidable gaps between electronic convenience and clinical accountability.

Why Password-Only Prescriber Login Fails as a Trust Boundary

Passwords alone can authenticate a session, but they do not reliably establish that the person entering the order is the person clinically authorised to do so. In prescription workflows, that matters because the security question is not just whether an account was accessed, but whether the prescriber’s identity and authority were strongly proven at the point of action.

A password is also too easy to reuse, share, phish, or capture from an exposed device. Once that happens, the workflow may still look “successful” from a system perspective while the accountability chain has already broken.

Where the Workflow and Clinical Accountability Split Apart

Online prescribing sits at the intersection of convenience, recordkeeping, and patient safety. If the only gate is a password, the workflow inherits the weaknesses of account hygiene, shared use, and credential compromise. That makes it harder to separate a legitimate prescriber action from someone acting under borrowed or stolen access.

This is why password-only designs create a false sense of assurance. They reduce friction, but they do not give the organisation a strong enough basis to say who approved the prescription, when that approval occurred, or whether the access path was appropriate for the clinical context.

That gap becomes more obvious when multiple staff members can access the same account, when temporary access is common, or when prescribers work across devices and locations. In those cases, the login mechanism no longer supports the level of attribution the workflow needs.

What Good Control Design Needs Instead

Prescribing systems need a control set that proves identity at the point of authorisation, not just at the point of login. That usually means stronger authenticators, better session protection, and explicit accountability for each order rather than relying on a shared or reusable secret.

Practically, the workflow should make it easy to answer three questions: who authorised the order, what assurance level supported that action, and whether the access path was consistent with policy. If the system cannot answer those questions, the control design is too weak for a high-consequence workflow.

Well-designed controls also reduce administrative ambiguity. They limit informal sharing, expose unusual access patterns, and make it easier to detect when a legitimate account is being used in an illegitimate way. For prescription systems, that is not a minor convenience issue; it is part of preserving clinical trust.

Risk and Threat Considerations

Password-only workflows are vulnerable to account sharing, phishing, credential stuffing, and replay of stolen access. In a prescribing context, those failures can turn a valid-looking transaction into an unauthorised clinical action, which increases fraud risk and weakens the audit trail needed for investigation or dispute handling.

Failure mechanism: The workflow trusts possession of a password as evidence of prescriber authority, so anyone who learns, reuses, or intercepts that password can submit orders that appear legitimate in the system.

Impact: The result is weaker non-repudiation, higher exposure to fraudulent or inappropriate prescriptions, and less reliable attribution when a prescribing decision must be reviewed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Prescriber login needs strong user authentication for accountable order entry.
IA-5 — Authenticator ManagementPassword-only workflows fail when credentials are shared, stolen, or poorly managed.
Recommendation — Use IA-2 to require strong authentication before prescriber actions are accepted. Use IA-5 to manage passwords, rotation, and recovery so credentials cannot stand alone as assurance.
NIST SP 800-63Digital Identity GuidelinesPhishing-resistant assurance and authenticators are central to trusted prescriber identification.
Recommendation — Apply NIST 800-63 assurance guidance to raise confidence above password-only login.
ISO/IEC 27001:2022A.5.16 — Identity managementPrescription accountability depends on clear identity ownership and traceability.
Recommendation — Establish identity management so each prescribing action maps to one accountable identity.
CIS Controls v8CIS-5 — Account ManagementShared or weakly governed accounts drive the accountability break in prescription workflows.
Recommendation — Harden account management to prevent shared access and improve auditability.

Practitioner Guidance

What to prioritise: Treat the login control and the prescribing decision as separate assurance problems. If the same credential can be used broadly, focus first on reducing account sharing and increasing the strength of the authenticator used at order time.

What to verify: Confirm that each prescription can be traced to a single accountable prescriber, that session records are retained, and that abnormal access patterns are visible enough to investigate quickly. If you cannot distinguish legitimate delegate use from direct prescriber action, the workflow is under-instrumented.

Common mistake: Teams often treat “successful login” as sufficient proof for a clinical workflow. For prescribing, the real test is whether the system can sustain accountability under password theft, shared access, and operational pressure.

Practitioner takeaway: For high-consequence workflows, a password can open the door, but it should not be the evidence that authorisation was correctly granted.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org