Healthcare password resets are an identity security issue

By:

Jonathan Allen
healthcare password resets are an identity security issue
Overview

Password resets may seem like a routine IT support task, but in healthcare they are also an identity security challenge. Health systems must verify identity quickly enough to minimize clinician downtime while protecting PHI, meeting compliance requirements, and reducing social engineering risk. This blog post explores how stronger identity verification can help organizations improve security, efficiency, and access workflows.

  • Healthcare password resets are fundamentally an identity verification, cybersecurity, and access management challenge.
  • Manual verification processes create friction for clinicians while increasing social engineering and impersonation risk.
  • Strong identity verification can reduce clinician downtime without weakening security or compliance controls.
  • Integrating CLEAR into the healthcare service desk workflow helps streamline password resets and improve auditability.
  • Identity verification can serve as the foundation for broader service desk automation, access management, and workforce security initiatives.

Password resets rarely get treated as a strategic issue in healthcare IT until they start slowing down clinicians, service desks, and patient-care workflows. Yet what appears to be a routine support request can quickly become a security, compliance, and operational challenge.

In nearly every health system I’ve worked with, password-related calls are among the most common reasons clinicians contact the service desk. A locked account can disrupt workflows, delay documentation, and create frustration for busy clinicians who simply need to get back to caring for patients. The reset itself is fairly easy; the harder part is verifying that the person asking for access is who they claim to be, without keeping a clinician waiting unnecessarily.

In this context, healthcare identity verification means confirming that the person requesting access is authorized before credentials are changed or access is restored. For service desks, that verification must be fast enough to avoid unnecessary clinician downtime and strong enough to preserve the confidentiality of protected health information (PHI), satisfy audit requirements, and reduce social engineering risk.

The obvious question is: Why can’t healthcare organizations handle password resets the same way consumers reset a password for a banking app or streaming service?

In healthcare, the difference comes down to the level of risk involved.

Why password resets carry higher stakes in healthcare

In many consumer settings, a password reset is mostly an inconvenience.

In a clinical environment, losing access to the EHR can affect documentation, orders, communication, and the ability to keep care moving.

Healthcare applications often contain PHI, medication orders, treatment plans, financial information, and other sensitive data. Access to these systems is governed by strict security controls and detailed audit requirements.

“It’s really hard to validate that a person truly is who they claim to be when every interaction happens remotely.”

quote icon

HIMSS Executive Roundtable participant

This is already showing up in day-to-day support workflows. Health systems are increasingly seeing identity-related attacks reach the service desk first, where threat actors attempt to impersonate clinicians, navigate internal processes, and exploit gaps in manual verification workflows. When attackers understand enough about the organization to answer basic questions or guide an analyst through familiar steps, traditional verification methods can become a weak point rather than a safeguard.

I’ve seen organizations put a lot of effort into training analysts to spot social engineering, and that work matters. But when an analyst is under pressure to help a clinician get back into the system quickly, the workflow itself needs to do more of the verification work. The process should not depend entirely on one person making the right judgment call in the moment.

Recent studies on healthcare cybersecurity reinforce why identity verification deserves more attention. The American Hospital Association reported that healthcare and public health was the top sector targeted for cyberthreats in 2025, with 460 ransomware attacks and 182 data breaches. The 2024 breach report from the U.S. Department of Health and Human Services Office for Civil Rights found that 663 large PHI breaches affected approximately 242.9 million people. The report also identified “person or entity authentication” as a key area for improvement. IBM’s 2025 Cost of a Data Breach research found that healthcare remained the costliest industry for breaches, with an average cost of $7.42 million and an average breach lifecycle of 279 days.

Part of the challenge is that healthcare identity is messy. Healthcare organizations may be supporting employed clinicians, affiliated physicians, contractors, vendors, students, external EHR users, remote workers, and patient-facing identities, each with different onboarding, validation, and access requirements. In many cases, the service desk is asked to make real-time access decisions without a complete view into who owns the identity, who verified it, and whether the person still needs access.

That leaves many health systems caught between two imperfect options:

  • Too little verification can expose the organization to inappropriate access.
  • Too much manual review can leave clinicians waiting while care is moving around them.

As a result, many health systems remain dependent on manual identity verification processes that can be exploited by sophisticated social engineering tactics, while also increasing resolution times and service desk workload.

“We’re getting blasted constantly, and it’s overwhelming the service desk.”

quote icon

VP of IT and Chief Information Security Officer, regional health system,

speaking during a HIMSS executive roundtable

The hidden cost of manual verification

In a typical healthcare environment, a password reset often involves:

  1. Calling the service desk
  2. Waiting for an analyst
  3. Answering identity verification questions
  4. Confirming employment or role information
  5. Performing the password reset
  6. Documenting the interaction for audit purposes

In practice, verification can involve a mix of knowledge-based questions, employment checks, HR system lookups, visual ID review, or escalation to someone who can confirm the caller’s identity. Each method may have a role, but all of them place a heavy burden on the analyst to make the right decision quickly, often while the clinician is waiting to regain access.

From the service desk side, this creates a difficult situation. Analysts are expected to be fast, helpful, security-conscious, and fully compliant at the same time. That is a lot to ask when the workflow still depends on manual checks, call scripts, and fragmented identity information.

Each step has a reasonable purpose, especially in an environment where access must be verified and documented, but the time adds up quickly. A routine reset can easily take 12–15 minutes or longer, depending on call volume, staffing, and the complexity of the verification process.

Across hundreds or thousands of password-related incidents each month, those minutes become real lost time for clinicians and support teams.

The effect is felt in practical ways:

  • Clinician downtime
  • Service desk workload
  • Increased labor costs
  • Frustrated end users
  • Longer wait times for higher-priority support issues

Many organizations have modernized large parts of the clinical technology environment while password reset workflows have remained largely unchanged.

Faster access doesn’t have to mean weaker security

Faster resets should not come from loosening safeguards or making verification less rigorous.

A faster workflow still needs strong identity verification, clear audit trails, compliance alignment, and role-based security. The person requesting access must be authenticated before credentials are changed, the reset must be traceable, and access rights should remain intact throughout the process. The goal is not fewer controls; it is a more efficient way to apply them.

“The goal is to automate as much of the process as possible and take the burden of authenticating identity away from the analyst.”

quote icon

HIMSS Executive Roundtable participant

The workflow has to work for clinicians

Even a well-built workflow can fall short if clinicians and affiliated users do not adopt it. Clinicians, contractors, and affiliated providers need to understand why the process is changing, how their information will be used, and what the new workflow means for day-to-day access. For physicians in particular, communication through clinical leadership, the CMIO, or the medical staff office can be as important as the technology itself.

HR, legal, compliance, privacy, and medical staff leadership should also be involved early, especially when biometric identity verification or employee consent is part of the workflow. The workflow will only succeed if users trust it enough to adopt it.

Where identity verification can reduce friction

Digital identity verification can take some of that burden off the service desk.

Instead of depending only on knowledge-based questions or analyst-led verification, organizations can use trusted digital identity verification to confirm identity earlier in the workflow.

When identity is validated before the reset reaches the service desk, clinicians can regain access faster while the organization maintains the needed documentation and controls.


This approach is especially relevant for healthcare organizations that:

  • Manage high volumes of password reset calls
  • Support clinicians, affiliated providers, external EHR users, contractors, or remote workers
  • Want to extend identity verification into service desk operations
  • Need stronger documentation around access requests
  • Want to reduce clinician downtime without weakening security controls

How Nordic and CLEAR are helping reduce reset times

Nordic has developed a unique integration with CLEAR’s identity verification platform that brings secure identity verification directly into the healthcare service desk workflow. Instead of treating identity proofing as a separate step, the integration allows callers to be validated within the contact center experience before they reach an analyst, with verification details documented in the ticketing workflow.

The value comes from bringing together pieces that often sit apart: CLEAR, the contact center, and the ticketing process. Together, they help give analysts confidence in the caller’s identity while preserving an audit trail. For health systems already using CLEAR, that means extending the value of their investment into day-to-day service desk operations.

Our goal with the Nordic/CLEAR integration was to solve the verification problem before the call reaches the analyst. When identity can be confirmed earlier and documented automatically, the service desk can spend less time proving who someone is and more time resolving the issue. In early use cases, this type of workflow has reduced password reset time from approximately 13-14 minutes to about two to three minutes.

Clinicians spend less time waiting, analysts spend less time validating identity, and security and auditability remain intact.

For health systems managing staffing constraints, rising support volumes, and persistent cybersecurity pressure, taking minutes out of a high-volume workflow can make a noticeable difference.

Password resets may be the starting point, but they are rarely the only identity workflow creating risk or friction. The same approach can support other high-volume, high-risk access moments, including remote access support, contractor validation, external EHR users, patient portal support, and workforce systems where identity compromise can have financial consequences. In healthcare, identity management now affects how quickly people can work, how safely access is granted, and how confidently the organization can respond to risk.

Protecting access without slowing care

Many healthcare organizations have treated password reset delays as an unavoidable part of maintaining secure access. But that tradeoff is starting to change. With the right identity verification workflow, health systems can protect patient data, support compliance requirements, and give clinicians a faster path back into the systems they rely on.

Reduce clinician downtime while strengthening identity verification. Learn how Nordic and CLEAR can help you modernize password reset and access workflows.

FAQ

Q: What is healthcare identity verification?

A: Healthcare identity verification is the process of confirming that a clinician, employee, contractor, or other authorized user is who they claim to be before granting access to systems, applications, or sensitive data.

A: Healthcare password resets involve access to systems containing PHI, clinical documentation, orders, financial data, and other sensitive information. Organizations must verify identity carefully while helping clinicians regain access quickly.

A: Password resets can become a target for social engineering when attackers impersonate clinicians or staff to gain access to protected systems. Manual verification puts pressure on service desk analysts to make fast, high-stakes identity decisions.

A: Digital identity verification can validate the caller earlier in the support workflow, reducing the time analysts spend on manual checks and helping clinicians regain access faster.

A: Healthcare service desks are often responsible for verifying identity before restoring access to critical systems and applications. Because attackers may attempt to impersonate clinicians or staff during password reset requests, service desks have become an important frontline defense against social engineering and unauthorized access.

A: Attackers often impersonate clinicians, employees, or contractors and attempt to convince service desk staff to reset passwords or restore access. Strong identity verification helps prevent unauthorized access and reduces impersonation risk.

A: Nordic has developed an integration with CLEAR’s identity verification platform that brings verification into the healthcare service desk workflow, allowing callers to be validated before they reach an analyst and documenting verification details in the ticketing process.

A: Health systems using CLEAR, organizations with high password reset volume, service desks supporting clinicians or affiliated providers, and teams managing remote access, external EHR users, contractors, or patient portal support can benefit.

A: Integrating CLEAR with the service desk allows identity verification to happen earlier in the support workflow. That can reduce manual verification, shorten password reset times, improve documentation, and help analysts resolve issues more quickly.

About the author

Jonathan Allen serves as VP of Customer Technology at Nordic Global, bringing more than 25 years of experience leading enterprise IT strategy, operations, and transformation. Prior to joining Nordic, he held leadership roles at Bon Secours Mercy Health, where he advanced technology and staffing standardization and led the insourcing of data center and telecommunications services. He holds a bachelor’s degree in Information Technology and several industry-recognized certifications.

Stay up to date on how healthcare’s changing and how we’re helping organizations change with it.

Join us for a night of networking

Join Nordic for an after‑hours networking happy hour at HIMSS. Connect with your chapter’s industry experts over great drinks and insightful conversation. This complimentary event is open to members of all HIMSS chapters.