Everyone agrees that stronger login protection for clinical software is a good idea. Where projects stumble is in the details: a nurse standing at a cart with a resident waiting, a badge that will not tap, or a vendor that supports one method but not another. Adding single sign-on (SSO) or multi-factor authentication (MFA) to an electronic health record deserves more planning than a typical IT change.
This post lists questions to settle before you begin. It is written for administrators and clinical leaders, with an eye toward the conversations you will have with your EHR vendor and IT team.
Do not assume. Ask your EHR vendor, in writing where possible:
Which sign-in methods are supported, and which are available to your organization and subscription?
Is MFA built in, or does it rely on your identity provider through SSO?
Are there additional costs, configuration requirements or limitations?
Can the approach apply to all users, including remote staff, physicians and outside therapists?
Settings and options vary and change over time, so rely on current vendor documentation and support instead of memory or assumptions.
Not every user and access path carries the same risk. Consider separate rules for:
Remote access. Logins from outside the building are a priority for MFA.
Administrative and privileged accounts. These should have the strongest protection.
On-site clinical staff at shared workstations. Here, speed and usability matter greatly.
Outside users, such as visiting physicians, consultant pharmacists or agency staff.
Many organizations apply MFA everywhere externally and use shorter, simpler methods on trusted, managed devices inside the building. Decide this deliberately and document why.
Walk through real situations with clinical staff before deciding anything.
How many times a shift does a nurse sign in or out? Will the new process add seconds or minutes?
What happens at a shared medication cart when two nurses need access?
Do staff use personal phones for MFA prompts? Is that acceptable to them and to your policy, and what about those without a smartphone?
Is there a fast option such as a badge, security key or similar method that suits clinical settings?
What about staff with gloves, masks or limited time during an emergency?
Pilot with a small group, then listen. If the process slows care, staff will find shortcuts, and shortcuts defeat the purpose.
Ask what happens when:
The identity provider or internet connection is down.
A staff member loses or forgets the device used for MFA.
A new hire needs access on day one.
A manager must reach the record during an emergency.
You need documented, tested procedures, including emergency access that is logged and reviewed. Your downtime plan for the EHR should account for authentication problems too.
SSO links accounts across systems, so duplicates, shared logins and stale accounts cause confusion. Before launching, clean up user lists and remove accounts for people who left. Shared logins should be eliminated, since they defeat both accountability and MFA.
Expect a spike in helpdesk calls. Prepare short instructions with screenshots, a clear contact number for each shift and a plan for extra support during launch week. Explain the reason: protecting resident information and keeping the facility running. Staff accept changes better when they understand them.
HIPAA's Security Rule expects access controls and authentication appropriate to your risk. Record your decisions, vendor responses, the pilot results and exceptions in your risk analysis. Review them at least annually.
Confirm vendor options and costs.
Define user groups and risk-based rules.
Clean up accounts.
Pilot on one unit and refine.
Roll out in phases with extra support.
Review problems and adjust after thirty to sixty days.
UnityCare IT can work with you and your EHR vendor to evaluate options, run a pilot and support your staff through the change. Our goal is stronger security that the floor can live with.
Keeping PointClickCare and other EHR systems fast, connected and available.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172