Back to Blog
Identity Security
9 min read

MFA Rollouts in Clinical Workflows: Avoiding Patient Care Delays

MFA fails in hospitals for workflow reasons, not technical ones. Shared workstations, gloved hands, no signal in the basement — and the factor choices that work anyway.

GuardsArm Team

Security Experts

December 17, 2025

MFA in clinical workflows

MFA rollouts in hospitals do not fail because the technology is hard. They fail because a clinician signs into a shared workstation forty times a shift, is wearing gloves, has no phone on the ward, and is standing in a basement with no signal. Ask that person to read a six-digit code off a device they do not have, and you have not added security — you have added a workaround.

40+ logins
Typical sign-in count per clinical shift on shared workstations
No phone
Many clinical roles cannot carry a personal device on the floor
Seconds matter
Authentication friction in an emergency is a patient safety issue, not an inconvenience

Match the factor to the setting

There is no single right second factor for a hospital. There are several, each suited to a different context.

SettingWorkable factorWhy
Shared clinical workstationBadge tap + PINOne tap, no phone, works with gloves
Personal clinical devicePlatform biometric / passkeyPhishing-resistant, no extra hardware
Remote administrative staffFIDO2 security key or authenticator appStandard, strong, no clinical constraint
Privileged / admin accessFIDO2 key, mandatoryHighest value target, no exceptions
Basement, shielded areasBadge or hardware OTP tokenWorks with no network or cell signal

Badge tap-and-go with a PIN is the control that makes clinical MFA viable. Staff already carry the badge. The reader sits on the workstation. The interaction is under two seconds, and it is genuinely two factors: something held and something known.

Push notifications are the wrong default here
Push approval depends on a phone, a signal and attention. On a busy ward it produces both delay and MFA fatigue — a clinician tapping "approve" reflexively, which is precisely the attack. Reserve push for administrative users, not the clinical floor.

The shared workstation problem

A single Windows session used sequentially by fifteen clinicians breaks the assumption behind most identity systems. The patterns that work:

  • Roaming sessions — the clinician's session follows their badge from workstation to workstation, resuming where they left off
  • Kiosk mode with fast user switching — a generic desktop session, with individual authentication into the clinical application
  • Application-level identity — the workstation is shared, but every action in the EHR is attributed to the individual who tapped in

The critical property is attribution. Whatever the mechanism, the audit trail must record the individual, not the workstation. Shared credentials defeat both the security control and the HIPAA audit requirement in one step.


Rolling it out without a revolt

Clinical MFA rollout sequenceClinical MFA rollout sequence1Pilot with a friendly unitWeeks 1-4One ward, badge readers installed, close support. Learn the workflow problems.2Administrative staff firstWeeks 4-8Lower clinical risk, builds operational experience with the platform.3Privileged accountsWeeks 6-10FIDO2 keys, mandatory, no exceptions. Highest value, smallest population.4Clinical rollout by unitMonths 3-6Unit by unit with on-floor support during the first shifts.5Remove the fallbacksMonth 6+Disable legacy authentication that bypasses MFA entirely.
The last step is the one most often skipped, and it is the one that makes the rest real.

That final phase matters more than it looks. Legacy authentication protocols bypass MFA completely. An organisation that has deployed MFA to every user but left legacy auth enabled has bought very little — attackers simply use the older protocol.


Break-glass, designed deliberately

Emergency access must exist. Design it rather than letting it emerge:

  • One clearly labelled path, available on every clinical workstation
  • No additional factor required — that is the point
  • Generates a real-time alert, not just a log entry
  • Reviewed within 24 hours, every time, by a named owner
  • Usage reported monthly, so a rising trend is visible

If break-glass is used routinely, that is information: the ordinary path is too slow, and the fix is the workflow, not more training.


Measuring whether it worked

  • Authentication time at the clinical workstation, 95th percentile — target under five seconds
  • Break-glass rate per unit, trending down after rollout
  • Help-desk volume for lockouts in the two weeks after each unit goes live
  • Legacy authentication attempts, which should reach zero
  • Phishing-resistant coverage for privileged accounts, which should be 100%

For the identity model these credentials feed into, see EHR security.

GuardsArm designs clinical MFA rollouts including badge integration and break-glass review processes. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.