CIS2 Authentication
CIS2 Authentication is the modern identity and access service within NHS Care Identity Service 2 that enables health and care professionals in England to securely access clinical systems, patient information, and other NHS services. As a core component of NHS Care Identity Service 2, CIS2 Authentication supports the NHS's broader digital transformation strategy by modernizing identity and authentication services, replacing the NHS's legacy smartcard-centric authentication model with internet-based identity services that improve security, usability, and interoperability. As part of the wider integrated care roadmap, CIS2 Authentication provides a modern authentication method for NHS and commercial healthcare applications. Supporting the smartcard-only system replacement in England, CIS2 Authentication uses the OpenID Connect (OIDC) standard, enabling software providers to integrate CIS2 with healthcare software APIs and national APIs while providing secure, standards-based access across modern clinical environments.
As NHS organizations continue their digital transformation, CIS2 Authentication helps ensure that secure identity verification evolves alongside modern clinical workflows and digital care delivery. Clinicians increasingly expect secure, frictionless access to clinical records, whether they are working at a desktop workstation, a shared device, a mobile device, or via dedicated apps. CIS2 Authentication supports this shift by enabling passwordless authentication and other strong authentication options beyond traditional smartcards, including biometric authentication through Windows Hello, passkeys, security keys, and other approved authenticators. Depending on the sensitivity of the application, systems can require either an AAL2 assurance level for high-confidence authentication or an AAL3 assurance level for very high-confidence authentication. This flexibility allows healthcare organizations to balance strong security with efficient clinical workflows while expanding cross-platform compatibility across a diverse healthcare technology ecosystem.
CIS2 Authentication works alongside role-based access controls (RBAC) managed through NHS Registration Authorities while supporting multifactor authentication (MFA) to strengthen authorization and governance. Applications that access user-restricted national APIs can leverage nationally managed RBAC assignments to ensure that clinicians only access information appropriate to their assigned roles, supporting auditability and regulatory compliance. Because CIS2 Authentication is built on modern identity standards rather than legacy network dependencies, developers can integrate CIS2 into new and existing healthcare applications while taking advantage of flexible session management, improved internet connectivity, and modern identity services. These capabilities help organizations introduce new digital technologies without requiring wholesale replacement of legacy clinical infrastructure, making modernization more practical across NHS trusts and integrated care systems.
Imprivata has a long history of supporting NHS organizations with healthcare identity and access management solutions that complement national initiatives such as CIS2 Authentication. Imprivata healthcare solutions help organizations deliver modern SSO for healthcare by enabling fast, secure access to clinical applications while supporting strong authentication, passwordless workflows, and streamlined clinician experiences. With extensive experience across hospitals and health systems, Imprivata solutions integrate with CIS2 and other healthcare software APIs to help healthcare organizations strengthen access security, reduce login friction, and align with NHS modernization goals while maintaining secure, reliable access to critical clinical systems.