Skip to content
A single shift at a single workstation is enough to show exactly where the authentication model stops working.

The Clinician Authenticated, Then Walked Away

One Ordinary Shift

At 6:58 a.m., a nurse authenticates into a workstation outside a patient's room, opens the EHR, and starts her morning assessment.

At 7:14, a call comes over the radio: a patient two doors down needs help right now. She leaves the workstation exactly as it was, screen open, session active, chart still on the display, and goes.

At 7:16, a colleague who was already walking past sits down at that same terminal to check a lab value before her own rounds start. She's authorized to be in the EHR. She was never authorized to be inside that specific session, but nothing on the screen tells her that, and nothing behind the screen checks either. She pulls up the value, closes the chart, and moves on to her next patient.

At 7:40, the first nurse comes back and logs into a session that never actually logged out, and finishes her note where she left it.

What the Audit Trail Won't Show

Nothing about that sequence looks unusual to anyone reviewing it later. Two clinicians touched one authenticated session. Both were legitimately allowed in the EHR. Neither did anything malicious, and neither broke a rule anyone had written down for them. The workstation's audit trail will show one clean, continuous login for the length of the shift, because that's what the workstation was built to show.

A Pattern, Not an Incident

This is the version of the identity gap that doesn't involve a stranger, a stolen badge, or an outside attacker. It's two authorized people sharing one identity envelope because the system had no way to tell them apart once the first one walked away. Multiply that across a twelve-hour shift, a unit with six workstations, and a hospital with dozens of units, and it stops being a single scenario and starts being a pattern that repeats every day, on every floor, without ever showing up as an incident.

The Fix Isn't Another Login

The fix isn't asking the second nurse to log in separately to check one lab value, that would slow down exactly the kind of quick cross-coverage clinical care depends on. The fix is a system that can tell, without asking anyone to do anything differently, that the person operating the session at 7:16 isn't the person who authenticated it at 6:58. That's what a continuous identity approach is supposed to catch, and it only works if something is actually watching the keyboard, not just the network or the device.

See the deployment data behind exactly this scenario: What's Hiding in Your Login Events

More from the Blog

Subscribe Here

We will never share your email address with third parties.