From 105 seconds to 10: fixing the shared-workstation login in hospitals

On a hospital ward one computer serves many clinicians, and each clinician uses many computers. A login designed for an office desk fails there, and staff find ways around it.

What the login costs

In January 2020 the UK government put £40 million into cutting NHS login times. It noted that some staff log into as many as 15 different systems. Its example was Alder Hey Hospital in Liverpool, where single sign-on cut the time spent logging in from 1 minute 45 seconds to 10 seconds. With almost 5,000 logins a day, that saved over 130 hours of staff time.

A larger study followed in October 2025. Researchers timed clinicians with stopwatches at 55 hospitals in the UK and Ireland, before and after single sign-on. Desktop login time fell by 60.5% on average and application login time by 51.2%. The authors estimate 3.3 million clinician hours freed each year across those hospitals, worth £54.1 million.

One caveat: the lead author advises Imprivata, which sells single sign-on, and three co-authors work there. The paper also says hospital leaders chose high-volume units for the measurements. The direction of the result is not in doubt, but the totals are best read as an upper estimate.

What staff do when the login is too slow

The classic study is Koppel and colleagues, 2015, titled "You want my password or a dead patient?". The researchers observed clinicians and recorded:

  • passwords on sticky notes, and whole units sharing a password taped to the device

  • Styrofoam cups placed over proximity sensors to stop automatic logout

  • junior staff told to keep pressing space bars so sessions would not time out

  • clinicians handing a logged-in session to the next colleague "as a professional courtesy"

The authors describe these staff as creative and motivated people trying to deliver care, not as rule-breakers. The result is the same either way. The audit trail names one person while another enters the order, and the next user may be working in the wrong patient's record.

What the rules expect

The EU's NIS2 Directive counts health among its sectors of high criticality. Article 21 lists "access control policies" and "the use of multi-factor authentication or continuous authentication solutions" among the measures entities must take.

In England the NHS MFA policy says organisations "must enforce strong MFA on all remote user access to all systems". It allows an exception where MFA "would create disproportionate clinical or operational risk or difficulty", but each exception must be documented, risk-assessed, approved at board level or as delegated, and reviewed regularly.

The policy's guide also points to an answer. NFC hardware tokens "can provide fast, convenient authentication in busy environments such as emergency departments".

What a good ward login looks like

  1. One identity per person. No ward accounts and no shared passwords, so every action in the record has a name.

  2. Seconds, not minutes. A tap of a card, key or wearable signs the clinician in, and the session follows them from one workstation to the next.

  3. Strong once, light after. A second factor such as a PIN or fingerprint at the start of a shift, then tap-only for a set period.

  4. Lock on walk-away. The session locks when the person leaves, so there is no long timeout to defeat with a cup.

  5. Fit for clinical conditions. It must work with gloves and masks, and without a personal phone.

  6. Break-glass access. Emergency access exists, is logged and is reviewed afterwards.

  7. Measured. Count logins per shift and seconds per login before and after, as Alder Hey did.

The takeaway

A security control that costs clinicians minutes gets bypassed. One that costs seconds gets used. The fastest route to strong authentication on a ward is to make the secure login the quickest one available.

Next
Next

NIS2 has reached the hospital: the access control evidence a supervisor will ask for