Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› When should healthcare teams prioritise passwordless access over…
Authentication, Authorisation & Trust

When should healthcare teams prioritise passwordless access over passwords on shared devices?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Authentication, Authorisation & Trust

Teams should prioritise passwordless access when clinicians use shared devices repeatedly during a shift and password entry creates lockouts, workarounds, or credential sharing. In that setting, passwords become a usability problem that turns into a security problem. Faster verified access usually reduces the incentive to bypass controls while preserving individual accountability.

Why passwordless wins on shared clinical devices

On shared workstations, the question is not whether passwords are familiar, but whether they are the best control for a fast, high-turnover workflow. Passwordless access is usually the better choice when the same clinician must unlock and relaunch applications repeatedly, especially if password entry is slow, error-prone, or encourages notes, shared logins, or session tailgating. The control should fit the clinical cadence, not fight it.

Passwordless approaches are strongest when the device, user, and session can be verified quickly and consistently, and when the team can avoid storing or reusing a secret at the point of care. That is where a phishing-resistant method such as passkeys or a hardware-backed authenticator often outperforms password reuse on a shared endpoint. For deployment details, teams can use the Passwordless and Passkeys Guide and the NIST SP 800-63 Digital Identity Guidelines.

That decision becomes especially important when the shared device is part of a repeatable shift pattern. If clinicians repeatedly authenticate to the same endpoint, the access method should minimise friction without collapsing into convenience-based exceptions. A workforce identity security guide is useful here because the practical issue is not only authentication strength, but how the workflow affects account recovery, session theft risk, and help-desk pressure. In other words, the best control is the one staff can follow under real clinical conditions.

When passwords still have a role

Passwordless should not be treated as a blanket replacement for every shared device scenario. If the environment has weak recovery processes, poor device trust, or frequent fallback to shared PINs and generic accounts, then the passwordless layer can become another place where exceptions accumulate. In those cases, the real problem is not the absence of passwords, but the lack of a reliable sign-in pattern that preserves individual accountability.

Passwords may still appear in the architecture for break-glass access, legacy applications, or temporary transition periods. The important distinction is whether they are part of the steady-state clinician workflow. When passwords are used as a daily convenience on shared endpoints, they tend to create the very behaviours healthcare teams are trying to avoid, including credential sharing and repeated lockouts. The better pattern is to keep password-based access out of the routine path wherever the application stack and policy allow it.

Healthcare teams should also distinguish between shared devices and shared identities. Shared devices can be acceptable; shared accounts usually are not. If a password is the only practical way to get quick access, teams often end up trading speed for auditability. Passwordless can preserve both by giving each user a personal, verified sign-in step while still allowing the clinical workstation to stay communal.

What good rollout looks like in practice

A useful rollout starts with the highest-friction shared workflows first, such as medication administration, bedside charting, and point-of-care documentation. Those are the places where repeated sign-in makes password fatigue most visible. The goal is to remove avoidable authentication steps without weakening who performed the action.

Teams should validate three things before they declare the rollout successful. First, the sign-in method must work reliably at shift pace. Second, it must survive device turnover, logout, and re-authentication without pushing staff toward workarounds. Third, recovery must be controlled so that a lost authenticator or locked profile does not send the unit back to shared passwords. For a broader hardening view, the Password Security and Password Manager Guide and the Identity Provider and SSO Security Guide help frame the surrounding controls.

Teams can also learn from breach patterns where weak or bypassed authentication on clinical or enterprise access paths created outsized impact. The lesson is not that passwords are always broken, but that repeated high-friction authentication on shared endpoints often invites the shortcuts attackers later exploit. Passwordless is most valuable when it removes the need for those shortcuts before they become normal practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines phishing-resistant, user-friendly authentication choices for repeated sign-in workflows.
Recommendation — Adopt phishing-resistant authenticators and align assurance to the shared-device workflow.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers password and authenticator lifecycle when replacing passwords on shared endpoints.
IA-9 — Service Identification and AuthenticationApplies when shared devices or clinical apps authenticate non-human services or backend sessions.
Recommendation — Manage authenticators so passwordless recovery and rotation stay controlled. Use strong service authentication where shared clinical devices depend on backend trust.
ISO/IEC 27001:2022A.5.17 — Authentication informationAddresses secure handling of authentication material in access workflows.
Recommendation — Protect authentication information and remove routine dependence on shared passwords.
CIS Controls v8CIS-5 — Account ManagementSupports reducing shared-account dependence and enforcing accountable access on workstations.
Recommendation — Use account management to eliminate shared credentials from routine clinical access.

Practitioner Guidance

What to prioritise: Start with the shared workflows that create the most repeated sign-ins per shift. If staff are re-entering passwords many times a day, the control is already at risk of being bypassed.

What to verify: Confirm that the passwordless method supports individual accountability, rapid re-authentication, and a clean recovery path. If recovery is clumsy, users will recreate the same friction through exceptions.

Decision rule: If password entry is causing lockouts, shared logins, or paper-based workarounds on shared devices, prioritise passwordless for that workflow and keep passwords out of the normal path.

Practitioner takeaway: On shared clinical devices, passwordless is worth prioritising when it improves both speed and auditability; if it merely replaces one inconvenience with another, the rollout is not ready.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org