Medical Device On-Prem IAM
A hospital ran Veripass fully on-premises to govern access to networked medical devices inside its clinical network, keeping identity, policy, and audit within its own walls.
A hospital ran a fleet of networked medical devices — infusion pumps, imaging consoles, monitoring stations — inside a segmented clinical network that, by policy, could not reach the public internet. The devices and their management consoles still needed governed access: who could operate them, who could change their configuration, and who serviced them. A cloud identity service was simply off the table.
The hospital needed full identity, authorization, and audit for its medical-device estate, running entirely within its own walls.
The challenge
Clinical network segmentation is a hard boundary, not a preference. Regulators and the hospital’s own security posture forbade routing device authentication or audit data through an external service. Yet the device estate had exactly the problems IAM exists to solve: shared technician logins on imaging consoles, no attribution for configuration changes on infusion pumps, and service vendors with standing access nobody reviewed.
They needed an identity platform that lived on-prem, integrated with the local directory, and never depended on an outbound connection to function.
What Veripass deployed
Veripass was deployed fully on-premises inside the hospital’s clinical network. Identities, policies, and the immutable audit trail all resided within the hospital’s own infrastructure, with no dependency on an external control plane. The local directory remained authoritative, federated over OIDC inside the network, so clinicians and technicians authenticated against credentials the hospital already governed.
Access to devices and their consoles was authorized through claims, capabilities, roles, and access profiles. A nurse operating an infusion pump, a technician changing its configuration, and a service vendor running diagnostics each carried a distinct profile evaluated by context-aware policy. Service vendors received scoped, time-boxed access rather than standing accounts, and every operation and configuration change was written to the on-prem immutable audit trail.
- Fully on-premises deployment inside the segmented clinical network
- Identity, policy, and audit residing within the hospital’s own infrastructure
- OIDC federation to the local authoritative directory, no outbound dependency
- RBAC from claims, capabilities, roles, and access profiles per device action
- Context-aware policy separating operate, configure, and service access
- Scoped, time-boxed access for service vendors instead of standing accounts
- On-prem immutable audit trail of every device operation and config change
For configuration changes on safety-critical devices, policy demanded a step-up: adaptive MFA over phone TOTP before a parameter could be altered, with the elevation recorded next to the change — all without a single packet leaving the clinical network.
Outcome
The hospital brought its medical-device estate under the same identity discipline as the rest of its systems, without violating network segmentation. Shared technician logins gave way to attributed access, configuration changes named a verified person, and service vendors lost their standing accounts in favor of scoped, expiring grants.
Every device operation and parameter change now lived in an on-prem immutable trail the hospital fully controlled — governed IAM for safety-critical hardware, delivered entirely inside its own walls.
More deployments
Edge Gateway Hybrid Deploy
A utility ran Veripass in a hybrid topology so on-prem edge gateways kept authenticating access during network outages while still federating to a cloud control plane for governance and audit.
Faculty & Staff Provisioning
A university automated the full lifecycle of faculty and staff access with Veripass SCIM provisioning and role-based entitlements, so accounts appeared on day one and vanished on departure.
Seasonal Staff Lifecycle
A luxury retailer automated identity provisioning and same-day deprovisioning for thousands of seasonal hires, closing the orphaned-account gap that holiday peaks used to leave behind.


