September 9, 2026

Authentication and the role of identity: Today, tomorrow and the future

Doctor holding checkmark

According to the PwC report Annual Threat Dynamics 2026: Cyber threats in motion, identity breaches are now the primary vector for cyberattacks. This is a global phenomenon across all industries. However, there are a number of operational factors that put healthcare at even more risk than other sectors. For instance, the tendency to use generic logins on shared devices due to the complexity of authenticating when wearing gloves, facemasks; or the time taken to remember and login to clinical systems when attention must be laser focused on treating very ill patients. Add to this the fact that patient data can be highly lucrative for criminals on the dark web, along with healthcare being an easier target due to less-protected login credentials, and it becomes irresistible to nefarious actors.

All of this was food for discussion when earlier this year we attended the spring Chime International CXO summit, where we hosted one of the workshops on ‘Healthcare Authentication and Digital Identity’. The session provided a very interesting snapshot of where we are now and what the future might hold for digital identity in healthcare.

What will replace traditional passwords?

It is a well-accepted tenet that passwords are old-fashioned (even impractical in certain circumstances), inherently insecure, and should be eliminated wherever possible. The way to do that is to harness digital identity and passwordless technologies as soon as possible. However, a consistent theme emerged during our workshop, revealing that the primary barrier to adoption is not the capability of the technology itself, but the way it is applied to clinical workflows and other organisational factors. While passwordless solutions (badges, biometrics, adaptive authentication) are both viable and available, successful implementation depends on training, governance, and clinician-centred design rather than innovation alone.

The core problem is if the security processes get in the way of busy clinicians, they will simply find a workaround, rendering the security almost pointless. Technology currently used for authentication can introduce inefficiencies into workflows, for example:

  • Repeated logins and multi-factor authentication (MFA) interruptions to time-critical tasks
  • Password complexity requirements (16 characters is not uncommon) which increase cognitive burden
  • Shared environments encourage informal workarounds such as credential sharing, which can be the only practical way to share a device on a busy ward.

These instances all highlight what happens when technology is not aligned with frontline workflows, often because clinicians were not involved at the design stage of the implementation for the new technology.

As well as raising the risk of a serious cyberattack, undermining security protocols can result in issues with data protection and patient safety standards, with no reliable audit trail to investigate or learn from should there be an incident.

How can organisations increase focus on digital ID authentication and transformation?

NHS England announced earlier this year that it is rebranding the Frontline Digitisation programme to Frontline Productivity, highlighting that digitisation is now largely delivered in most NHS trusts and that the focus must shift to achieving better productivity and value from the investment. With this focus, digital identity becomes even more important. Indeed, repositioning authentication as a clinical enabler, rather than a compliance function, will help to shift thinking. This will help healthcare organisations to transition towards solutions that deliver real benefits to the frontline, including:

  • Near-instant access in clinical workflows
  • Robust identity assurance and auditability
  • Minimal cognitive and operational burden (if it’s easy for clinicians, it saves the helpdesk too because there are far fewer password resets, for example)

How can passwordless access help healthcare organisations become more secure?

The appetite to move to passwordless within the NHS is there but putting it into operation remains a challenge. The role of authentication is evolving and we are seeing a clear maturity pathway emerging:

  • Legacy – Username and password
  • Intermediate – Single sign-on (SSO) and password
  • Target state:
    • Passwordless authentication
    • Badge-based access
    • Biometrics (facial or fingerprint)
    • Adaptive authentication (additional MFA in non-standard circumstances)

Imprivata Advanced and Passwordless Access brings together features that address many of the issues faced by NHS trusts looking to galvanise their existing investment in digital and realise productivity gains and end-user benefits.

Imprivata supports three pillars of stronger digital identity security:

  • Stronger access control including robust authentication at the point of registration using technology such as facial recognition and FIDO2 security keys
  • ID verification that ensures the person is who they claim to be, for example, during password resets
  • Adaptive authentication that ensures the pattern of access is trusted, i.e. from a known location at an expected time of day. Anything outside of normal parameters is challenged with the requirement for additional MFA.

New functionality such as facial biometrics, FIDO passkeys, identity verification, VPN-less access, identity detection and threat response bring innovative technology that delivers intelligence and automation. This approach gives a better user experience while also removing some of the burden on the IT department.

What are the benefits of passwordless access security to clinicians, patients and the organisation?

Moving to passwordless security delivers many benefits. It increases security and protection in a way that is transparent to the end user. This is becoming more important as the threat landscape continues to evolve.

Social engineering techniques used to get personal details and credentials are not new, but the speed and scale at which criminals are now able to compromise identities and gain access has changed dramatically, often taking just minutes. AI is accelerating this shift further. It is now far easier to weaponise these vectors, particularly ID verification, for example, with cloned voices and deepfakes, making strong authentication more important than ever.

Imprivata Advanced and Passwordless Authentication helps to provide access to patient information when it is needed, without creating weaknesses in the system that can potentially be exploited. It does all this in a way that protects patient data, protects clinician credentials, and protects the organisation. Should the worst happen and credentials are stolen, the damage that can be caused is limited.

5 key conclusions about the current state of authentication and traditional password use:

Discussions at the Chime event confirmed the current state of play for the use of authentication, with the conclusions as follows:

  1. Passwords are no longer viable in clinical environments
  2. Passwordless solutions are achievable but can be operationally complex
  3. The primary barrier is adoption – not technology
  4. Security must be designed around clinical workflows
  5. Trust, governance, and training and critical enablers.

In a rapidly evolving digital agenda, there is really no choice but for healthcare organisations to improve protection for digital identities.

Learn more about modernising access in healthcare.

You are currently browsing

Product availability varies by region. Would you like to choose a different region?

No thank you, I'd like to continue