Skip to content
Twosense CEO & Co-Founder Dawud Gordon Ph.D. and Sandy Vance talk through why clinical passwordless projects stall, the session-level risk that remains after passwords are gone, and what a top 10 U.S. health system learned rolling it out to 17k+ users.

Why Passwordless Stalls in Hospitals, and What It Takes to Finish the Job

Our team hears some version of the same story from almost every health system it talks to: a passwordless pilot goes well with back-office staff, the project moves toward the clinical floor, and somewhere between the first unit and the second it loses momentum and gets pushed to next year's budget. Our CEO and co-founder, Dawud Gordon, Ph.D., recently joined host Sandy Vance on the Cybersecurity at ViVE series from HLTH's The Beat podcast to talk through why that keeps happening and what it takes to get past it. The episode, Solving Healthcare's Passwordless Problem, was released September 16, 2026.

The conversation builds on the case study Dawud presented at ViVE 2026, the health IT conference hosted by HLTH and CHIME in Los Angeles this past February, which covers a 90-day passwordless deployment with one of our customers, a top 10 U.S. health system. Below are Sandy's questions and Dawud's answers, with added context from our team where it helps. Quotes have been lightly edited for length and clarity.

Why does passwordless matter for health systems right now?

Sandy Vance: "Let's talk first about why passwordless matters for health systems right now."

Dawud Gordon: "They're undergoing a lot of compliance changes that have been moving through the world of enterprise in general, but are now arriving at health systems, that require complex, longer passwords. Implementing a change like that across a clinical workforce is something you immediately experience at the help desk, with people forgetting passwords, rotating them, and having to reset them. And for the clinicians themselves, that's an extra six, seven, eight characters they need to type every time they want to access PHI. That password is now standing between the clinician and delivering care to a patient, and it's just gotten longer."

Dawud added that this is the point where many health systems decide the password is "no longer a problem that we can just accept or a risk that we can accept." For a clinician moving from room to room and completing a break-the-glass flow at each stop, those extra characters add up across every shift.

Why do so many passwordless projects stall?

Sandy Vance: "What makes these projects difficult to pull off? A lot of projects get started and then stall out. Why is that?"

Dawud Gordon: "Most of these health systems have extremely proficient security and IT teams, but the industry is making the assumption that passwordless is a solved problem. Any identity and security vendor you talk to is going to have a passwordless SKU. Health systems will see initial results that look really good with the non-clinical population, the back office, even the security teams themselves. Then they try to transfer that into a clinical environment, and that's a shared workstation environment. On one machine you'll have multiple users in a single day, and every user interacts with multiple workstations throughout the day. Any solution you select for the non-clinical population is going to work great until you get into that clinical environment."

The result is the pattern Sandy summed up: the clinicians who need passwordless most are the ones who never get it. Dawud described how it plays out in a typical pilot, where a clinician enrolls at one workstation, moves to the next, and is asked to enroll again because the system sees "a new user on a new workstation." Projects go in circles until, in Dawud's words, someone says, "We don't have enough time in this cycle to figure that out, so let's put that on hold for the 2028 budget."

What does Twosense do differently?

Sandy Vance: "How is Twosense deploying this solution and making a difference? What are you doing differently that's helping organizations get this right?"

Dawud Gordon: "Every single human being knows and hates that it's your job to do the work of typing in your password or getting a text or doing whatever it takes to authenticate. We take that and automate it so that it happens invisibly in the background. It's a fully passive user experience. There is no user experience. And once it's fully automatic, you can run it once a second, every second, in a way the user doesn't see, so a factor that would normally be a password, a passkey, or another badge tap becomes invisible. You get a full multi-factor and passwordless experience that feels like a reCAPTCHA to the end user."

The part that matters most for clinical environments is what Dawud said next: "Once it gets frictionless, you don't just do it when somebody's logging into something. You can do it continuously across the entire session." That's what Continuous Authentication, powered by passive behavioral biometrics, is built for. When a clinician opens a patient record that requires step-up authentication, that check happens in the background instead of interrupting care.

What risk remains on shared clinical workstations?

Sandy Vance: "What are some of the risks you're mitigating on clinical workstations that are passed around from user to user? What does that risk look like, and how is this helping provider organizations?"

Dawud Gordon: "What we see in production is that the biggest type of compliance violation is not something malicious. For the most part, it's an accidental session-sharing event, where one clinician who is trying to help a patient doesn't realize that somebody else has already badged into the workstation they're using. Neither the person whose account is open nor the person using it in the moment is aware of it. And the investigation that incident creates takes the same amount of time as if it was a malicious attack."

Dawud described how simple the fix can be when the system detects a behavioral mismatch in the moment: "'Hey, this is Dawud's account. This doesn't look like it's Dawud. Are you sure you're on the right account?' And you can just click yes or no." If the clinician clicks no, they're switched out and can badge back in as themselves. As Dawud put it, "That is a monstrous compliance issue that's just been avoided by having a very simple remediation."

What does success look like?

Sandy Vance: "What does success look like for a health system that's solved both the login problem and the session-level risk problem? You presented a pretty compelling case study at ViVE. Share a bit of that with our listeners."

Dawud Gordon: "The case study comes from a top 10 U.S. health system, a fully integrated academic medical center, so it's one of those very complex environments where they'd really struggled to eliminate passwords. By getting rid of those passwords, they took the number of times a clinician is trying to sign into something and just can't, and reduced that by 89%. That was the big internal metric that had the most meaningful resonance with their internal stakeholders. It also resulted in a 79% reduction in identity-related help desk tickets, mostly 'I forgot my password' or 'I have to reset my password.' And they rolled this out across 17,000 users."

Dawud also pointed to the result that's easiest to overlook: "What's hidden in there is that 100% of the sessions those users are working in across their day are now protected with continuous authentication." For the security team that owns the rollout, that's the difference between securing the login and securing the entire session.

What did the implementation look like for IT?

Sandy Vance: "Nobody in IT wants more tickets, so the reduction is a big deal. But what about the actual process of getting this installed?"

Dawud Gordon: "That was the thing they were actually most worried about when we got started. Even switching from one 2FA app to another, just changing the color of the app's logo on managed clinical devices and having people click it once to start a new enrollment, is a major change management concern, because you know there will be people who don't figure out that the green app is now a red one. Each one of those results in a failed login. What this health system did, which was really a method they pioneered, was to take our capability and roll it out passively in the background. The user doesn't even realize they're being enrolled. It's learning to recognize them based on their behavior, and usually somewhere between three work days and about two weeks, they become enrolled."

Once enrollment was complete, IT switched it on, and Dawud described it as "almost like a gift that they get to give to their population." The calls that followed weren't about which app to open. In his words, they were, "What did you guys do? I think something might be broken. The passwords are all gone."

How is AI shaping Twosense's strategy?

Sandy Vance: "Here we are in Q3 2026, the age of AI. What's your strategy as CEO for leveraging AI within your tools, and how might that carry the company forward?"

Dawud Gordon: "My background is in machine learning and artificial intelligence, and our product is an AI-native product. You can't look at somebody else's typing behavior or mouse movements and say, 'Oh, that's Sandy.' That's uniquely suited to a machine learning solution. What we're seeing now is that AI tools are being used both inside organizations and by people outside trying to get in. You can do a very sophisticated phishing attack against an individual, but now you can do that against every individual, all in parallel. And if you have folks creating agents, that agent usually has their authorization. It becomes incredibly important to know that the agent is on a session where the user who kicked it off is the authorized user."

Dawud expanded on where this is heading. As the industry locks down non-human identities and agent permissions, "these persistent attacking or malicious workflows are getting pushed more into trying to impersonate the user and go through the user's channel." He called it "the next frontier," one some of our more advanced customers are already preparing for, where the question becomes whether the person in the session is the authorized user, another human, or a bot.

What's your one piece of advice for teams considering this technology?

Sandy Vance: "What's the one piece of advice you'd give to folks thinking about engaging with this type of technology?"

Dawud Gordon: "As you're designing how this system is going to work, think about non-clinical and clinical in the same frame, because a user who's in the clinical environment goes into their office and is now in a non-clinical environment. And think about what you'd want to prove to your most important, loudest, most annoying clinical users that would take them from pushing back against security changes to being your advocate. If you can accomplish that, you can turn your top clinician, your chief of medicine, into somebody who will pull this into the environment, rather than you as a security team needing to push it."

Going Further: The Case Study and the Peer Forum

The complete results are in our health systems case study, which adds detail the podcast only touched on, including more than 1 million passwordless logins, 173 critical applications protected, and a 100% software-only deployment. Our team can't name the health system for contractual reasons, but as Dawud explained on the episode, "This is not just a vendor and a product pitch. This is really a new methodology that they've pioneered for themselves and are now sharing with others." Their team has built a peer forum, which our team hosts, where they talk through that methodology with other health systems.

If you'd like an introduction, you can reach out to Dawud directly or via LinkedIn.

Beyond Healthcare: What a Banking Customer Showed Us

When Sandy asked whether Twosense would be able to get ahead of AI-driven impersonation for our customers, Dawud's answer was that "our customers are already getting ahead of that." Our team recently shipped support for the Continuous Access Evaluation Profile (CAEP), the open standard within the OpenID Foundation's Shared Signals Framework (SSF), which Dawud described as a way to "broadcast is this Sandy, yes or no, through an enterprise ecosystem." That trust signal lets each system in a customer's identity stack act under its own policy, whether that means re-authentication, step-up authentication, locking or terminating the session, or another remediation action. Dawud shared that one of our customers in the banking sector walked him through how they were using it: "They were like, 'This is what we're doing.' And I was like, 'That's amazing. I never even thought about that.'" Knowing who is actually at the keyboard matters anywhere access is shared, delegated, or high-stakes, and customers outside healthcare are finding uses for that signal on their own.

Conclusion

Dawud's conversation with Sandy on HLTH's Cybersecurity at ViVE series, building on the 90-day deployment he presented at ViVE 2026, comes back to a point our team makes often: clinical passwordless isn't stalling because health systems lack capable teams or tools. It stalls because most passwordless approaches still ask the user to do the work of authenticating, and shared workstations multiply that work until the clinical rollout collapses under it.

Our customer, a top 10 U.S. health system, finished the job by taking that work off the user entirely, enrolling 17,000+ users without asking anything of them, cutting failed logins by 89% and identity-related help desk tickets by 79%, and extending protection past the login to every session where accidental sharing, and increasingly AI-driven impersonation, actually happen.

For health systems that have already been around the passwordless track once or twice, the finish line depends less on removing the password than on making authentication continuous, so it holds up on the clinical floor and not only in the pilot.

Listen to the full episode, or read our health systems case study for the complete results.

More from the Blog

Subscribe Here

We will never share your email address with third parties.