Skip to content
In a hospital, the real exposure lives in the gap between who logs in and who's still using the session minutes later.

Your User Passed MFA, But What Happens After They Authenticate?

The Question Authentication Was Never Built to Answer

Every hospital CISO has spent the last several years hardening the login. Multifactor authentication, single sign-on, and passwordless rollouts have made it substantially harder for the wrong person to get into an EHR, a billing system, or a privileged admin console in the first place. That work matters, and it should continue.

But authentication only answers one question: did the right person get in? It has nothing to say about who is still at the keyboard ten minutes later.

A Gap Nothing Is Designed to Notice

That gap is easy to miss because nothing in the system flags it. A nurse authenticates into a shared workstation at a nursing station, opens a chart, and gets called away mid-task. A registration employee logs into a terminal, steps away to help a patient at the front desk, and leaves the screen unlocked. An IT administrator opens a privileged session and takes a call in the hallway. In every one of these cases, the identity provider's logs still show a clean, successful authentication. The session is still marked valid. Nothing in the audit trail says otherwise, because nothing was designed to notice that the person operating the session might have changed.

This Is How Health Systems Actually Runs

Clinicians move between patients and rooms all day, shared workstations exist because requiring every employee to carry a personal device isn't realistic in a hospital, and registration, revenue cycle, information management, and IT all depend on the same shared, always-on terminals. Interruption is the normal operating condition, not the exception.

The Scale of What Stays Exposed

The scale of what's exposed while that gap stays open isn't small. Health systems reported breaches affecting roughly 138.5 million individuals in 2025, and hacking or other IT incidents accounted for more than 80% of large breaches that year, according to HHS's Office for Civil Rights breach data. Unauthorized access and disclosure incidents, the category that includes someone using an account or session they weren't authorized to use, rose in 2025 after several years of decline. OCR's public data doesn't break out how many of those incidents involved a session left open after the authorized user walked away, but the scenario this piece is describing, valid credentials being used by someone other than the person who authenticated, sits squarely inside that category.

More Login Prompts Isn't the Fix

The instinct when a gap like this shows up is to add another authentication step. Require a badge tap to unlock. Shorten the timeout. Prompt for a PIN again after five minutes of inactivity. Some of that helps at the margins, but it also adds friction to a workday that already asks clinicians and staff to authenticate dozens of times a shift, and friction is exactly what pushes people toward the workarounds security teams are trying to prevent in the first place: shared logins, propped-open sessions, workstations nobody bothers to lock.

The more useful fix isn't asking the user to prove their identity more often. It's giving the organization a way to know, continuously, whether the identity that authenticated is still the identity operating the session, without adding another interruption to do it.

Security vendors have started calling this shift continuous identity: evaluating whether trust still holds for as long as a session runs, not just at the moment someone logs in. Most continuous identity approaches on the market today still stop short of answering the specific question this piece opened with, whether the person at the keyboard is still the person who authenticated, because generating that signal from human behavior is a harder problem than moving data between systems that already trust each other. That's the piece worth sitting with before adding the next authentication control: not how to make the login stronger, but how to make identity assurance last as long as the session does.

See how Twosense's Continuous Authentication Platform approaches this problem: Explore Continuous Authentication for Health Systems.

More from the Blog

July 23, 2025

Continuous Authentication: Keeping Clinicians Focused on Patients, Not Passwords

In hospitals, clinicians are under constant pressure—not just from patient loads or administrative tasks, but from the...
April 11, 2022

BREAKING: What You Need to Know About PCI DSS 4.0

In 2006, the Payment Card Industry Security Standard Council (PCI SSC) launched a set of requirements to ensure that...
July 16, 2025

Why Clinical Identity in Hospitals Is So Hard — and How Continuous Authentication Solves It

In Healthcare, Identity Is a Clinical Problem—Not Just a Security One In hospital environments, authentication is...

Subscribe Here

We will never share your email address with third parties.