Clinician EHR Single Sign-On
A hospital network gave clinicians one federated sign-on across the EHR and clinical applications, cutting repeated logins at the bedside while keeping every access policy-governed and audited.
A hospital network ran an electronic health record alongside a dozen specialty clinical applications — imaging, pharmacy, lab, scheduling — each with its own login. A physician moving between patients re-authenticated constantly, often on a shared workstation, and the friction pushed staff toward password sharing and unlocked sessions. Every shortcut a clinician took to save time chipped away at attribution.
The network wanted one federated sign-on across every clinical application, fast enough for the bedside, without loosening who could see what.
The challenge
Clinical software is heterogeneous and slow to change. The EHR spoke SAML; newer apps spoke OIDC; some only understood directory accounts. Identity was scattered, so deprovisioning a departing clinician meant chasing accounts across systems, and there was no single audit answering which applications a given clinician had actually opened during a shift.
They needed a control plane that federated all of it under one identity per clinician, honored each app’s protocol, and kept access bound to role and context.
What Veripass deployed
Veripass became the identity provider in front of the clinical estate. Clinicians authenticated once against the hospital tenant — federated to the existing directory over OIDC — and Veripass brokered sign-on into each downstream application using whatever protocol it required: SAML for the EHR, OIDC for modern apps, SCIM to keep accounts provisioned and deprovisioned in step.
Authorization was expressed through claims, capabilities, roles, and access profiles. A resident, an attending, and a pharmacist each carried a different profile, so single sign-on never meant uniform access — it meant one authentication resolving into precisely the applications and scopes each role was entitled to. Every sign-on and app launch was written to an immutable audit trail.
- One federated sign-on across the EHR and clinical applications
- SAML and OIDC brokering per downstream application
- OIDC federation to the hospital’s existing clinician directory
- SCIM provisioning and deprovisioning across clinical systems
- RBAC from claims, capabilities, roles, and access profiles per clinical role
- Adaptive, step-up MFA over phone TOTP for high-sensitivity actions
- Immutable audit trail of every sign-on and application launch
For high-sensitivity actions — opening a restricted record, e-prescribing a controlled substance — policy demanded a step-up: adaptive MFA over phone TOTP before the session was elevated, logged alongside the access. Routine charting stayed friction-free so the security control matched the risk of the action.
Outcome
Repeated bedside logins collapsed into one authentication, and the password-sharing workarounds that came with them faded because signing in was no longer the bottleneck. Deprovisioning a departing clinician became a single upstream action that cascaded through SCIM across every clinical app, closing the orphaned-account gap.
The network gained one consolidated, immutable trail of which clinician opened which application, under which role, and where they had to step up — turning EHR access from a patchwork of disconnected logins into one governed, auditable surface.
More deployments
Campus-Wide Student SSO
A university gave every student one login for the entire campus stack by federating Google Workspace and the student directory through Veripass, ending the credential sprawl across portals and services.
Fingerprint Turnstile Entry
A manufacturing site replaced badge tailgating at its turnstiles with fingerprint biometric verification bound to identity, so every entry proved the person was physically present and authorized.
Maison Loyalty Verification
A luxury maison protected its high-tier loyalty program with biometric identity verification at enrollment and step-up at redemption, stopping account takeover of accounts holding significant stored value.


