Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should teams do when shared mobile devices…
Governance, Ownership & Risk

What should teams do when shared mobile devices are causing delays at the point of care?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Focus on containment at the workflow level before expanding the programme. Stabilise device handoff, improve application availability, and make identity state recoverable after each use so clinicians can return to care quickly without improvising access. The goal is to remove the need for exceptions before they become normal practice.

Contain the workflow before the device programme grows

When shared mobile device slow care at the point of care, the first move is to stabilise the handoff pattern, not to add more process around it. Treat the device as part of the clinical workflow: predictable sign-out, predictable reset, and predictable return to the next user. If clinicians have to improvise access, the delay will spread beyond the device itself.

A practical response is to reduce the number of moving parts after each use. That means shortening the steps needed to hand the device back, reducing state that must be remembered by the next user, and making the device reliable enough that staff do not work around it.

Where delays are caused by access friction rather than hardware failure, stabilising the operating workflow matters more than issuing new instructions. The goal is not more control layers, but fewer opportunities for delay to accumulate at the bedside.

Make the device easy to recover between users

The most useful test is whether the next clinician can use the device without inheriting the previous user’s state. That includes the app session, cached access, and any local residue that forces manual cleanup. If state recovery is unreliable, the device will become a queue point instead of a care tool.

Teams should design for rapid re-entry after each handoff. In practice, that means closing the previous session cleanly, clearing what should not persist, and restoring only the minimum needed for the next authenticated use. A shared device should behave like a temporary work surface, not a long-lived personal endpoint.

Digital identity recovery and strong re-authentication become important when the same device is used by many clinicians in succession, because the point is to recover quickly without weakening assurance. If the workflow only works when people reuse state, the design is too brittle for clinical use.

Remove the conditions that turn delay into normal practice

Shared devices usually become a bottleneck when exceptions start to feel routine. The warning sign is not just slowness, but a growing pattern of workarounds: shared PINs, informal logins, manual bypasses, or staff keeping a device longer than intended because re-entry is painful. At that point, the issue is no longer a device problem alone, it is a workflow control problem.

Teams should watch for two things: how often the handoff breaks down, and how often clinicians compensate by bypassing the intended process. If the workaround is what keeps care moving, the underlying workflow is already failing. The right response is to fix the handoff and recovery path, not to accept exception behaviour as operationally normal.

When the environment includes shared access to clinical applications and patient-facing data, privacy and data governance also depend on that recovery being reliable. A delayed workflow can push teams toward broader access, longer sessions, or weaker controls, which increases exposure as well as friction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesShared-device recovery depends on reliable re-authentication after each use.
Recommendation — Use phishing-resistant, low-friction re-authentication for every user handoff.
NIST CSF 2.0PR.AA-05 — Access Permissions and AuthorizationsShared clinical devices need tight, recoverable access state between users.
Recommendation — Limit active access to the current user session and clear residual access promptly.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe workflow hinges on managing credentials and session-reset behaviour after shared use.
IA-2 — Identification and Authentication (Organizational Users)Clinical staff must re-establish identity cleanly after each shared-device handoff.
Recommendation — Set short-lived, tightly managed authenticators for shared-device workflows. Require strong user authentication at each handoff before clinical access resumes.

Practitioner Guidance

What to prioritise: Fix the handoff sequence before trying to optimise every downstream clinical application. If the device cannot be reset, re-authenticated, and handed to the next user quickly, the rest of the programme will inherit the delay.

What to verify: Test the full return-to-use path under real shift conditions, including app availability, session recovery, and the time required for a clinician to resume care after another user finishes. If the recovery path depends on manual cleanup, it is not yet operationally stable.

Common mistake: Treating shared-device delay as a training issue when the real failure is in the workflow design. Training helps only after the underlying handoff and recovery steps are simple enough to repeat consistently.

Practitioner takeaway: The right bar is not “can we make the device usable again,” but “can we restore safe, fast, repeatable use without exceptions becoming the normal operating model.”

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org