The condition where a device's active session no longer matches the clinician currently using it. In healthcare, this usually happens when logouts are missed, credentials are reused, or handoffs are informal, creating a gap between operational reality and access control.
What Shared-Device Identity Drift Means in Practice
Shared-device identity drift is not a device fault so much as a state mismatch: the screen may look “in use,” but the active access context belongs to a different person than the one physically operating the device. That creates a gap between operational reality and access control.
In practice, the drift usually emerges during fast-paced handoffs, missed logouts, or reused sessions. The device becomes a shared access surface, so the security question is not whether the hardware is trusted, but whether the current session still reflects the correct human operator.
Why It Happens on Clinical Devices
Clinical workflows encourage speed, continuity, and interruption tolerance, which makes session hygiene easy to miss. A nurse, technician, or physician may inherit a logged-in workstation or handheld device, then continue work without a clean re-authentication boundary.
That pattern is reinforced when teams treat the device as the unit of trust instead of the person, or when the workflow lacks strong session handoff, timeout, or re-entry requirements. NHIMG’s Device and IoT Identity Guide is a useful reference point for the broader principle that device trust has to be lifecycle-aware, not assumed from possession alone.
Security Consequences of a Mismatched Session
When the logged-in session no longer matches the current clinician, the system can misattribute orders, charting, medication access, or audit trails. That is a security issue because the access decision is now detached from the real operator, which weakens accountability and can hide misuse or error.
Shared-device identity drift can also expand the blast radius of a simple workflow mistake. If one user leaves a live session behind, the next user may inherit privileges, data visibility, or application state that should have ended with the prior user.
For identity lifecycle and session hygiene patterns, NHIMG’s NHI Lifecycle Management Guide and Top 10 NHI Issues both reinforce the same control principle: stale access contexts are a governance problem even when the underlying identity is technically valid.
How Organisations Should Interpret the Term
Shared-device identity drift should be read as an operational control failure, not just a usability nuisance. The core issue is whether the environment can reliably re-establish who is acting before sensitive functions are used again.
That makes the term especially relevant in settings where device sharing is normal and auditability matters. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a helpful companion when you need to think about evidence, traceability, and accountability around access activity.
How It Differs From Simple Shared Access
Shared access is the broader condition where multiple people legitimately use the same endpoint. Identity drift is narrower and more dangerous: the problem is that the active session or authentication state is no longer aligned with the person actually using the device.
That distinction matters because a device can be appropriately shared and still be out of control if the session boundary is not reset. In other words, the risk is not the shared hardware itself, but the moment when the system stops knowing which clinician is effectively behind it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Covers re-authentication of users on shared clinical workstations. |
| IA-5 — Authenticator Management | Addresses session and authenticator handling when credentials are reused or left active. | |
| AC-2 — Account Management | Supports lifecycle control over active accounts and session continuity on shared endpoints. | |
| Recommendation — Require fresh authentication before a new clinician inherits an active session. Manage authenticators so shared devices do not retain usable access across handoffs. Review and deactivate lingering access paths that survive a device handoff. | ||
| NIST CSF 2.0 | PR.AA-05 — Protective Technology, Identity Management and Access Control | Directly aligns with preventing access-context drift on shared devices. |
| PR.AA-01 — Identities and Credentials Are Issued, Managed, Verified, Revoked, and Audited | Covers identity lifecycle hygiene that prevents stale sessions from persisting. | |
| Recommendation — Apply access-control safeguards that tie clinical activity to the correct user session. Audit identity and session lifecycle events so shared devices cannot keep stale access alive. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org