Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why does workflow fit matter as much as…
Authentication, Authorisation & Trust

Why does workflow fit matter as much as compliance when implementing EPCS?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Authentication, Authorisation & Trust

Because EPCS succeeds only when clinicians will actually use it at the point of care. A compliant authentication method that creates too much friction leads to resistance, workarounds, and delayed adoption. The operational impact is real: prescribing becomes slower, provider satisfaction drops, and the programme can fail even if it meets the rule on paper. Compliance is necessary, but usability determines whether the control is sustained.

Why workflow fit is part of EPCS control design

EPCS is not just an authentication decision, it is a clinical workflow decision. If the control adds delay at the bedside, disrupts prescribing rounds, or forces staff to switch context too often, clinicians will find ways around it or avoid using it consistently. That means the control can be compliant on paper while still failing in practice because the real requirement is sustained use at the point of care.

A good fit starts with the task sequence, not the policy statement. The authentication step has to align with how prescribers actually move through ordering, verification, and sign-off, including shared workstations, interruptions, and time pressure. If the design assumes a neat desktop workflow but the real environment is mobile, noisy, or team-based, friction becomes the failure mode.

workflow fit also determines whether the control is operationally sustainable. The more frequently clinicians must stop, re-authenticate, or recover from failed prompts, the more likely they are to delay orders, batch activity, or ask others to work around the process. For EPCS, those behaviours matter because the prescription is often time-sensitive and the user experience is part of the control’s effectiveness.

Where compliance alone falls short

Compliance tells you the method meets a rule; it does not tell you whether the rule can survive daily use. In EPCS, that gap shows up when a technically valid solution imposes enough burden that adoption stalls or workarounds emerge. The practical question is not only whether the authentication is acceptable, but whether it is usable under clinical pressure.

This is why implementation teams should treat resistance as a control signal, not just change-management noise. If clinicians are repeatedly failing to complete prescriptions, asking for exceptions, or relying on informal shortcuts, the organisation is seeing evidence that the implementation path is misaligned with care delivery. The programme may still be secure, but it is not yet operationally fit.

Fit matters especially where the process depends on shared clinical infrastructure. A control that works in a quiet office can become fragile on shared workstations, during shift handoffs, or when the prescriber is interrupted mid-task. In those conditions, a small usability problem turns into a broader adoption problem, which then becomes a security and safety problem because the prescribed path is no longer the path people choose.

What good EPCS implementation looks like in practice

Good EPCS design reduces friction without weakening assurance. That means choosing an authentication flow that matches the actual prescribing context, measuring where users slow down or abandon the process, and testing the flow in real clinical settings rather than only in a demo environment. The control should be reliable enough that clinicians can complete the task without feeling forced into a workaround.

For healthcare identity and access controls, NHIMG’s Healthcare Identity Security Guide is a useful reference point because it connects clinician access, shared workstations, and EPCS to the operational realities that determine whether security controls are actually used.

It also helps to separate minimum compliance from durable adoption. A rollout can satisfy the rule set while still needing refinement in timeout settings, step counts, device handling, or exception handling. Teams should expect iterative tuning, because the best control is the one that clinicians can complete correctly every time, not the one with the most elegant policy language.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)EPCS prescriber authentication must be usable for clinicians at the point of care.
IA-5 — Authenticator ManagementEPCS implementation depends on managing authenticators without creating excessive user friction.
Recommendation — Use IA-2 to ensure clinician authentication is strong enough for prescribing yet practical in clinical workflows. Use IA-5 to manage authenticators so EPCS users can complete authentication reliably without unsafe workarounds.
ISO/IEC 27001:2022A.5.15 — Access controlEPCS is an access-control decision where policy must align with operational use.
Recommendation — Align access control policy with the actual prescribing workflow so compliant access remains usable.
NIST SP 800-63Digital Identity GuidelinesEPCS authentication design depends on assurance and usability trade-offs for human users.
Recommendation — Apply digital identity guidance to balance assurance level with the clinical user journey.
CIS Controls v8CIS-5 — Account ManagementEPCS depends on controlled, usable account and authenticator handling for clinicians.
Recommendation — Review account workflows to reduce friction that drives unsafe EPCS workarounds.

Practitioner Guidance

What to prioritise: Measure real completion time, failure points, and workaround frequency for the prescribing flow before treating the control as finished. If the authentication step regularly interrupts care, the design still needs work even if audit language is clean.

Decision rule: If the control can be bypassed informally or causes repeated delays in live use, treat workflow redesign as a security requirement, not a usability enhancement. In EPCS, adoption failure is itself a control failure.

What good looks like: Prescribers can complete EPCS without assistance, without avoidable retries, and without creating side channels for approval or signing. The control feels embedded in care delivery rather than bolted onto it.

Practitioner takeaway: EPCS succeeds when compliance and workflow fit reinforce each other, but operational fit is the factor that determines whether the control survives contact with daily clinical practice.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org