Back to Blog
Identity Security
9 min read

SSO and Session Management for Healthcare Apps

Single sign-on solves the login. Session management is what decides whether the next person at that workstation is still signed in as you — and in a hospital, someone always is.

GuardsArm Team

Security Experts

January 3, 2026

SSO and session management

Single sign-on is the easy half. A clinician authenticates once and reaches the EHR, the PACS viewer, the lab system and the scheduling tool without typing a password again. The hard half is the opposite question: when does that access stop? On a shared workstation in a corridor, the answer decides whether the next person to walk up is operating as the last person who logged in.

Shared by default
Clinical workstations serve many users in sequence, often without a clean handoff
Attribution
Every EHR action must map to an individual — a stale session breaks that
45 CFR 164.312(b)
Two clocks
Idle timeout and absolute lifetime solve different problems and both are needed

Two timeouts, two different jobs

Teams routinely configure one and assume it covers both cases.

Idle timeout ends a session after a period of no interaction. It protects the abandoned workstation. In clinical areas it needs to be short — minutes, not hours — which is exactly why it is unpopular and why it needs a fast way back in.

Absolute lifetime ends a session a fixed time after sign-in regardless of activity. It bounds the damage from a stolen token, which idle timeout alone does not: an attacker replaying a token keeps it alive indefinitely by using it.

ContextIdle timeoutAbsolute lifetime
Shared clinical workstation2-5 minutesShift length
Personal clinical device15 minutes12 hours
Administrative desktop15-30 minutes12 hours
Remote / VPN access15 minutes8 hours
Privileged session5 minutes1-2 hours
A short idle timeout needs a fast return path
Cutting the clinical idle timeout to three minutes without badge tap-to-resume produces workarounds within a week — a wedged keyboard key, a mouse jiggler, a shared account. Pair the two changes or do neither. See MFA in clinical workflows.

Proximity and the clean handoff

The mechanism that actually resolves shared-workstation sessions is badge-driven:

Badge-driven session handoff on a shared workstationEach clinician taps to resume their own session; walking away or the next tap locks the previous session, so actions stay attributable to an individual.Tap insession resumesWorkattributed to userTap out / walk awaysession locksNext user tapstheir own session
Roaming sessions follow the clinician between workstations rather than being rebuilt each time.

The property that matters is not convenience, it is attribution. If two clinicians share one Windows session, the EHR audit trail can still be correct provided the application authenticates individually — but if it does not, you have lost the ability to answer who viewed a record. That is both a security failure and a HIPAA audit-control failure.


Single logout is usually broken

SSO federates login. Logout is much weaker in practice. A clinician clicking "sign out" of the EHR frequently leaves the identity provider session and every other federated application still live. The next person taps the browser and is inside the lab system.

What to verify in your own estate:

  • Does signing out of one application terminate the IdP session?
  • Do the other federated applications actually honour the logout propagation?
  • Does closing the browser end the session, or just hide it?
  • Does locking the workstation end application sessions, or only the desktop?
  • How long does a refresh token remain valid after the user signs out?

Test this by hand. Sign into three applications, sign out of one, then return to the others. The result is often surprising.


Token lifetimes are the silent risk

SSO issues tokens, and a token is a bearer credential: whoever holds it is the user. Long-lived refresh tokens are convenient and are precisely what an attacker wants from a compromised endpoint.

  • Keep access tokens short — an hour or less
  • Bound refresh token lifetime, and make it single-use with rotation
  • Revoke on password reset and on termination — and confirm revocation actually invalidates existing sessions rather than only blocking new logins
  • Bind tokens to the device where the platform supports it, so a stolen token is not portable
  • Re-authenticate for sensitive actions regardless of an existing session
The termination test
Disable an account in the directory, then try the application with an already-issued token. On many estates the session keeps working until the token expires. That gap is the one that matters on the day somebody is walked out of the building.

What to check this month

CheckTarget
Idle timeout on clinical workstationsUnder 5 minutes, with badge resume
Absolute session lifetimeBounded, not "until browser closes"
Single logout propagates to all appsVerified by hand, per application
Access token lifetime1 hour or less
Session survives account disableNo — revocation is immediate
Shared session without individual app authNone

GuardsArm reviews SSO and session configuration across clinical application estates, including the single-logout and revocation behaviour that vendors rarely document accurately. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “SSO and Session Management for Healthcare Apps”

Talk to the GuardsArm team about how these services apply to your environment.