Join our Newsletter — 33% off our NHI Course
Home› Glossary› NHI Lifecycle Management› Shared-device identity drift
NHI Lifecycle Management

Shared-device identity drift

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: NHI Lifecycle Management

The condition where a device's active session no longer matches the clinician currently using it. In healthcare, this usually happens when logouts are missed, credentials are reused, or handoffs are informal, creating a gap between operational reality and access control.

What Shared-Device Identity Drift Means in Practice

Shared-device identity drift is not a device fault so much as a state mismatch: the screen may look “in use,” but the active access context belongs to a different person than the one physically operating the device. That creates a gap between operational reality and access control.

In practice, the drift usually emerges during fast-paced handoffs, missed logouts, or reused sessions. The device becomes a shared access surface, so the security question is not whether the hardware is trusted, but whether the current session still reflects the correct human operator.

Why It Happens on Clinical Devices

Clinical workflows encourage speed, continuity, and interruption tolerance, which makes session hygiene easy to miss. A nurse, technician, or physician may inherit a logged-in workstation or handheld device, then continue work without a clean re-authentication boundary.

That pattern is reinforced when teams treat the device as the unit of trust instead of the person, or when the workflow lacks strong session handoff, timeout, or re-entry requirements. NHIMG’s Device and IoT Identity Guide is a useful reference point for the broader principle that device trust has to be lifecycle-aware, not assumed from possession alone.

Security Consequences of a Mismatched Session

When the logged-in session no longer matches the current clinician, the system can misattribute orders, charting, medication access, or audit trails. That is a security issue because the access decision is now detached from the real operator, which weakens accountability and can hide misuse or error.

Shared-device identity drift can also expand the blast radius of a simple workflow mistake. If one user leaves a live session behind, the next user may inherit privileges, data visibility, or application state that should have ended with the prior user.

For identity lifecycle and session hygiene patterns, NHIMG’s NHI Lifecycle Management Guide and Top 10 NHI Issues both reinforce the same control principle: stale access contexts are a governance problem even when the underlying identity is technically valid.

How Organisations Should Interpret the Term

Shared-device identity drift should be read as an operational control failure, not just a usability nuisance. The core issue is whether the environment can reliably re-establish who is acting before sensitive functions are used again.

That makes the term especially relevant in settings where device sharing is normal and auditability matters. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a helpful companion when you need to think about evidence, traceability, and accountability around access activity.

How It Differs From Simple Shared Access

Shared access is the broader condition where multiple people legitimately use the same endpoint. Identity drift is narrower and more dangerous: the problem is that the active session or authentication state is no longer aligned with the person actually using the device.

That distinction matters because a device can be appropriately shared and still be out of control if the session boundary is not reset. In other words, the risk is not the shared hardware itself, but the moment when the system stops knowing which clinician is effectively behind it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Covers re-authentication of users on shared clinical workstations.
IA-5 — Authenticator ManagementAddresses session and authenticator handling when credentials are reused or left active.
AC-2 — Account ManagementSupports lifecycle control over active accounts and session continuity on shared endpoints.
Recommendation — Require fresh authentication before a new clinician inherits an active session. Manage authenticators so shared devices do not retain usable access across handoffs. Review and deactivate lingering access paths that survive a device handoff.
NIST CSF 2.0PR.AA-05 — Protective Technology, Identity Management and Access ControlDirectly aligns with preventing access-context drift on shared devices.
PR.AA-01 — Identities and Credentials Are Issued, Managed, Verified, Revoked, and AuditedCovers identity lifecycle hygiene that prevents stale sessions from persisting.
Recommendation — Apply access-control safeguards that tie clinical activity to the correct user session. Audit identity and session lifecycle events so shared devices cannot keep stale access alive.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org