MFA Rollouts in Clinical Workflows: Avoiding Patient Care Delays
MFA fails in hospitals for workflow reasons, not technical ones. Shared workstations, gloved hands, no signal in the basement — and the factor choices that work anyway.
GuardsArm Team
Security Experts
MFA rollouts in hospitals do not fail because the technology is hard. They fail because a clinician signs into a shared workstation forty times a shift, is wearing gloves, has no phone on the ward, and is standing in a basement with no signal. Ask that person to read a six-digit code off a device they do not have, and you have not added security — you have added a workaround.
Match the factor to the setting
There is no single right second factor for a hospital. There are several, each suited to a different context.
| Setting | Workable factor | Why |
|---|---|---|
| Shared clinical workstation | Badge tap + PIN | One tap, no phone, works with gloves |
| Personal clinical device | Platform biometric / passkey | Phishing-resistant, no extra hardware |
| Remote administrative staff | FIDO2 security key or authenticator app | Standard, strong, no clinical constraint |
| Privileged / admin access | FIDO2 key, mandatory | Highest value target, no exceptions |
| Basement, shielded areas | Badge or hardware OTP token | Works with no network or cell signal |
Badge tap-and-go with a PIN is the control that makes clinical MFA viable. Staff already carry the badge. The reader sits on the workstation. The interaction is under two seconds, and it is genuinely two factors: something held and something known.
The shared workstation problem
A single Windows session used sequentially by fifteen clinicians breaks the assumption behind most identity systems. The patterns that work:
- Roaming sessions — the clinician's session follows their badge from workstation to workstation, resuming where they left off
- Kiosk mode with fast user switching — a generic desktop session, with individual authentication into the clinical application
- Application-level identity — the workstation is shared, but every action in the EHR is attributed to the individual who tapped in
The critical property is attribution. Whatever the mechanism, the audit trail must record the individual, not the workstation. Shared credentials defeat both the security control and the HIPAA audit requirement in one step.
Rolling it out without a revolt
That final phase matters more than it looks. Legacy authentication protocols bypass MFA completely. An organisation that has deployed MFA to every user but left legacy auth enabled has bought very little — attackers simply use the older protocol.
Break-glass, designed deliberately
Emergency access must exist. Design it rather than letting it emerge:
- One clearly labelled path, available on every clinical workstation
- No additional factor required — that is the point
- Generates a real-time alert, not just a log entry
- Reviewed within 24 hours, every time, by a named owner
- Usage reported monthly, so a rising trend is visible
If break-glass is used routinely, that is information: the ordinary path is too slow, and the fix is the workflow, not more training.
Measuring whether it worked
- Authentication time at the clinical workstation, 95th percentile — target under five seconds
- Break-glass rate per unit, trending down after rollout
- Help-desk volume for lockouts in the two weeks after each unit goes live
- Legacy authentication attempts, which should reach zero
- Phishing-resistant coverage for privileged accounts, which should be 100%
For the identity model these credentials feed into, see EHR security.
GuardsArm designs clinical MFA rollouts including badge integration and break-glass review processes. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


