Not Just the Nursing Station
When health systems security teams talk about shared workstations, the image that usually comes to mind is a nursing station: one terminal, a rotating set of clinicians, a shift that doesn't stop long enough for everyone to have their own device. That image is accurate, but it's also incomplete. Shared, always-on terminals are a fixture of how health systems operate well outside the nursing unit.
Shared Terminals Are Everywhere in Health Systems
A pharmacy runs on a small number of terminals shared across a rotating staff, because verifying and dispensing medication happens at fixed stations, not at individual desks. A laboratory or imaging department relies on shared workstations positioned next to the equipment itself, because the alternative, carrying a personal device between machines all shift, doesn't fit the workflow. Scheduling and registration desks are staffed in shifts on shared terminals for the same reason nursing stations are: the work happens at a fixed location, and the person doing it changes throughout the day. Workstations on wheels extend the same model into hallways and patient rooms across departments that have nothing to do with direct clinical care.
A Relationship That's Constantly Turning Over
In every one of these settings, the relationship between a person, a workstation, and a session is constantly turning over, and the identity architecture treats that turnover as invisible. A session authenticated by a pharmacy technician at 9:00 doesn't know that a different technician is standing at the same terminal by 9:20. A scheduling desk doesn't distinguish between the employee who logged in that morning and whoever is physically there when a patient walks up at 2:00 in the afternoon.
Redesigning the Environment Isn't the Answer
The instinct to solve this by redesigning the environment, giving every pharmacy technician a personal device, eliminating shared terminals in imaging, doesn't hold up against how these departments actually run. Shared computing exists in health systems because the alternative isn't practical, not because anyone overlooked a better option. Trying to engineer it away adds cost and friction without addressing the actual gap, which isn't the hardware, it's the identity layer sitting on top of it.
Put the Check on the Identity, Not the Device
The workable answer treats the shared workstation as a permanent feature of the environment and puts the identity check where it belongs: on the person using the session, continuously, rather than on the device itself at the moment someone first sits down. That's the piece a continuous identity strategy has to get right in health systems specifically, because nowhere else does the person behind a session change this often.