Continuous authentication in healthcare: verifying clinicians after sign-in

Hospitals check who a clinician is once, when they sign in. Continuous authentication keeps checking for the rest of the session.

A clinician in teal scrubs stands at a shared workstation in a busy hospital, colleagues moving past in a blur

Hospitals have spent a decade fortifying the moment of sign-in. The larger risk sits in the hours that follow, when nobody checks who is actually using the clinician's computer.

In brief

  • In healthcare, a valid sign-in says who sat down, not who is using the session hours later. Sessions are routinely left open, handed off and shared.
  • When the person and the account part company, patient records are exposed and the audit trail records the wrong clinician.
  • TruU Continuous Authentication uses behavioral biometrics (how a person types and uses the mouse) to verify the user throughout the session, in the background.
  • Organizations choose the response by policy: monitor-only, or enforcement with on-device step-up authentication and automatic session lock.
  • Every change in behavioral risk is audited, giving security and privacy teams evidence of who was actually present.

At the start of a clinic day a physician opens her assigned laptop, signs in and opens the electronic health record. By any reasonable standard she has been authenticated. For the next several hours every system she touches will assume she is still the one using it. That assumption is rarely tested, and in a hospital it is often wrong.

The cause is less negligence than the shape of clinical work. Doctors and nurses are interrupted constantly. They leave a laptop open mid-note to attend to a patient and return twenty minutes later, or not at all. Colleagues step in to help finish the work. And security that obstructs care tends to lose. In a 2015 study pointedly titled “You Want My Password or a Dead Patient?”, Ross Koppel and colleagues catalogued how clinicians defeat access controls that slow them down, down to putting Styrofoam cups over proximity sensors so that screens would not lock.

Three ways a valid sign‑in goes wrong in hospitals

Healthcare security teams describe the same three situations, each of which leaves an authenticated session in the hands of someone who was never verified.

The walk‑away
The clinician leaves the workstation, the session stays open, and whoever passes next is working under her name.
The hand‑off
The clinician signs in, then a colleague, resident or scribe takes over the keyboard.
The borrowed login
Someone who knows the clinician’s credentials signs in as her while she is elsewhere entirely.
Each case leaves a valid session in the hands of someone who was never verified.

The outcome is the same in each case. Patient data, and every application reachable through single sign-on, is open to an unverified user.

Why the audit trail is the real casualty

Worse, the access log names the wrong person. HIPAA’s Security Rule asks covered organizations to verify that a person seeking access to electronic health information is who they claim to be, and to keep audit controls that record activity in those systems. Most hospitals satisfy both at the point of sign-in. But an audit trail is only as reliable as the identity attached to it. When the account and the person behind it part company, a privacy investigation begins from false evidence, and a clinician may be held to account for a chart she never opened. In a profession built on knowing who saw which patient’s record, that is no technicality.

Why inactivity timeouts are not enough

The Security Rule’s own session safeguard is automatic logoff after a period of inactivity, and it does not require continuous authentication. Inactivity timeouts address only the walk-away, and crudely. Set them short and clinicians are locked out mid-task and find ways around them; set them long and the unattended screen stays open. They do nothing about the hand-off or the borrowed login, because neither setting says anything about who is typing.

What is continuous authentication?

Continuous authentication verifies a user’s identity for the whole session rather than only at sign-in. Instead of demanding proof once and trusting it thereafter, it keeps asking whether the person at the device is still the person who signed in.

TruU Continuous Authentication answers that question with behavioral biometrics. It learns how each clinician types and moves the mouse, the rhythm and timing that are personal and hard to imitate, and then compares whoever is at the keyboard with the person it has learned. This happens in the background; the clinician is asked to do nothing. One mechanism covers all three cases. A passer-by at an abandoned terminal does not type like the physician. Nor does the colleague who took over after she signed in, nor the person using her borrowed password. Knowing the right credentials is no help, because credentials are not what is being checked.

How TruU responds when the user doesn’t match

Detection is worth little unless something follows from it. The response is set by each organization’s policy and applied automatically on the device.

Monitor‑only
Mismatches are recorded and nobody is interrupted. Security teams use it to map where sessions are shared or left unattended before deciding how strict to be.
Enforcement with step‑up authentication
A mismatch holds the session. Step-up authentication covers the screen, and nothing behind it can be reached until the user gives a valid PIN or biometric on the device itself; no phone is required. A clinician who answers carries on where she left off. If the answer is wrong, or nobody answers in time, the session locks.
Risk‑based single sign‑on
The same behavioral risk assessment governs access to other applications. While behavior keeps matching, single sign-on continues without additional authentication. When behavior drifts, the next application asks for stronger proof before it opens.
Responses are set by organizational policy and applied automatically on the device.

Friction rises with doubt: little for the clinician who is plainly herself, more for a session that has begun to look like someone else’s.

A continuous audit trail of who was present

Every change in behavioral risk is recorded as it happens, not only the moments that end in a lock. Each of the following is logged as an event tied to a user and a device.

Behavioral drift
The user’s behavior moves away from the clinician’s normal pattern.
Policy threshold crossed
Risk reaches the level the organization set for action.
Step‑up authentication
Step-up authentication is required, then passed or failed.
Session locked
The device locks after a failed or unanswered step-up.
Every change in behavioral risk is recorded, not only the moments that end in a lock.

This gives security and privacy teams something sign-in logs have never offered: evidence of who was actually present during a session. When a question arises about access to a patient record, they can see whether behavior matched the account holder at that time, and what the device did about it. In monitor-only mode, the same events show where shared logins and unattended sessions occur across the organization.

Design principles: how TruU Continuous Authentication fails closed

A security control is defined as much by its edge cases as by its model. Five choices determine how this one behaves when things go wrong.

Signing in does not switch off the behavioral check
If a successful login silenced the check, the hand-off would be invisible. Authentication at sign-in and behavioral verification remain independent.
A failed or missing answer locks the session
Wrong credentials, a timeout or no available authenticator all end in a lock. Closing step-up authentication is not a way out.
Missing or invalid policy means enforce
If the configured mode is missing or invalid, the product enforces rather than standing down, so a configuration error cannot quietly disable the control.
No judgment before the model knows the user
A newly enrolled clinician is not judged against a model that has yet to learn her. Until it has, access to other applications requires stronger proof, not less.
Typed content stays private
Keystrokes in a hospital carry clinical detail, and window titles can contain patient names. The model uses how someone types, not what they type, and window titles are not stored.
Five choices that decide how the control behaves when something goes wrong.

Frequently asked questions

What is continuous authentication?

Continuous authentication verifies a user's identity throughout a session rather than only at sign-in. TruU Continuous Authentication does this with behavioral biometrics: it learns how each person types and uses the mouse, and compares whoever is at the keyboard with that learned pattern in the background.

Do clinicians have to do anything differently?

No. The behavioral check runs in the background. A clinician is only asked to act if their behavior stops matching and the organization's policy calls for step-up authentication.

Does TruU Continuous Authentication record what clinicians type?

No. The model uses how someone types, such as rhythm and timing, not what they type. Window titles, which in a hospital can contain patient names, are not stored.

Can it run without interrupting anyone?

Yes. In monitor-only mode, mismatches are recorded and nobody is interrupted. Security teams can use it to see where sessions are shared or left open before turning on enforcement.

What happens when the person at the keyboard doesn't match?

With enforcement on, step-up authentication covers the screen and the session is held until the user gives a valid PIN or biometric on the device. No phone is needed. If the step-up fails, times out or cannot be completed, the session locks.

How does it affect single sign-on to other applications?

While behavior keeps matching, single sign-on continues without extra prompts. When behavior drifts, the next application asks for stronger proof before it opens.

How are new users handled?

A new user is not judged against a model that has not yet learned them. Until it has, access to other applications requires stronger proof rather than less.

From sign‑in security to session security

In a working day where a clinician’s session is left open, handed over and shared, the more useful question is who is using it now. Continuous authentication lets a hospital ask it every minute, keep a record of each answer, and decide in advance what should happen when the answer changes.

About this article

This article draws on conversations with healthcare security teams and on shipped product behavior. No customer data is included. Sources:

  • Koppel, R. et al., “Workarounds to Computer Access in Healthcare Organizations: You Want My Password or a Dead Patient?”
  • HIPAA Security Rule, 45 CFR §164.312(b) (audit controls) and §164.312(d) (person or entity authentication).
← All postsSchedule a Demo