What is IAM as it applies to the healthcare sector?
IAM (Identity and Access Management) refers to the set of processes and tools used to manage who has access to what within an information system. In healthcare facilities, this issue takes on a special significance.
A hospital is not a typical business. Healthcare staff work 24/7, with positions shared among several employees. Staff profiles vary widely: salaried physicians, private practitioners, temporary staff, part-time workers, external service providers, and administrative personnel. Some work at multiple sites within the same Regional Hospital Group (GHT), with different roles depending on the facility. A surgeon, for example, might hold a management role at one hospital and a clinical role at another.
Line-of-business applications are also specialized: EHR (Electronic Health Record), prescription software, bed management systems, imaging, laboratory, and patient administrative management (PAM). Each has its own access rights and authorization levels. These tools are rarely interconnected: PAM does not communicate with the EHR, and the EHR does not communicate with bed management. Each application operates in a silo, with its own accounts, its own passwords, and no overall view. The HOP'EN 2 program confirms this: the fragmentation of hospital information systems is identified as a structural barrier to the quality and safety of care.
IAM in healthcare is the building block that ties it all together: a single identity repository, connected to HR systems, that centralizes all of the institution’s applications and links application accounts to their users. One healthcare provider, one identity, consistent access rights across all applications.
The Practical Problems That Arise When a Facility Does Not Have an IAM
The risks associated with not having an IAM are not merely theoretical. They occur on a daily basis in organizations that manage their accounts manually.
Accounts that no one deactivates. Organizations with high turnover automatically accumulate active user accounts belonging to employees who have left. This phenomenon is observed in hospitals, as well as in staffing agencies and fire and rescue services: the more frequent staff turnover is, the more orphaned accounts pile up if there is no automated process to deactivate them. In a context where cyberattacks against hospitals are on the rise, every orphaned account is a potential entry point. In February 2021, a ransomware attack on the Dax Hospital Center took the entire information system offline for several weeks. According to ANSSI’s analysis, the attackers gained access to the facility’s directory and acquired domain administrator rights within a few hours, which allowed them to deploy the ransomware on multiple servers simultaneously.
Generic accounts that prevent any traceability. Four nurses sharing the same “nursing station” username in the EHR: this is still a reality in many facilities. It’s impossible to know who accessed which patient record, impossible to conduct a thorough audit, and impossible to comply with the GDPR. The goal of traceability for access to health data becomes a pipe dream.
Entire groups of people fall off the radar. Private practitioners, physical therapists, and temporary staff do not go through the standard HRIS system. Their arrival is not always reported to the IT department, and their departure even less so. These “non-HRIS” groups sometimes account for 20 to 30 percent of users of the information system in clinics and medical-social facilities.
Siloed applications with no common repository. EPR, GAP, bed management, imaging, lab results, and prescribing software: each application has its own user directory, its own access rules, and its own account creation processes. When a healthcare professional joins the team, the IT department must manually set up their access in each system. When they leave, the IT team has to remember to revoke access one by one. Without a centralized identity repository, inconsistencies multiply, and the IT department loses visibility into who has access to what.
Unmanageable access reviews. Compliance requires regularly verifying that each user has access only to what they need. Without a centralized tool, this review must be conducted application by application and department by department. For IT teams that are already understaffed, this is a colossal task, one that is often postponed or done halfheartedly.
Fragmented governance across multiple sites. In healthcare and social services groups or hospital groups (GHTs), each facility has its own practices, its own IT administrators, and sometimes its own directories. The central IT department lacks a consolidated view of all accounts and access rights. Authorization rules vary from one site to another without any consistency.
Here is what the IAM actually does in a school:
What Regulations Now Require of Institutions
The HospiConnect program, led by the French Digital Health Agency (ANS) as part of HOP'EN 2 and the CaRE program, requires healthcare facilities to follow a clear path for identity management. Four operational requirements form the framework of the program: registering all healthcare professionals in a local directory compliant with the RPPS, implementing an IAM module to manage access permissions and the account lifecycle, deploying strong authentication (SSO, MFA), and connecting to Pro Santé Connect for access to the DMP.
The deadlines have been set. The framework document was to be submitted by June 26, 2026. The first technical requirements for doctors and nurses take effect in June 2027. Full implementation for all EHR users is scheduled for June 2028.
But HospiConnect isn’t the only framework. The HOP’EN 2 program also includes a “call for proposals” component that funds projects aimed at closing the digital maturity gap and improving time management and HR processes—two areas that directly intersect with identity management. Here is an overview of the requirements and funding:
The key point for a hospital CIO: HospiConnect and HOP'EN 2 are currently the only frameworks that come with funding. This presents a window of opportunity to launch an IAM project that meets all requirements at once—not just those of HospiConnect.
How IAM Is Transforming the Day-to-Day Work of IT Teams and Healthcare Providers
The value of an IAM solution goes beyond simply checking off regulatory requirements. Its impact is felt on a daily basis, both by IT teams and by healthcare professionals.
From the CIO’s Perspective: Regaining Control of the Lifecycle. Automated provisioning is a game-changer. An event in the HRIS (hiring, transfer, departure) automatically triggers the creation, modification, or suspension of accounts across all connected applications. Youzer, for example, automates this lifecycle by connecting to the organization’s HR data sources, including for personnel outside the HRIS (private practitioners, temporary staff) who are registered via forms with an approval workflow and expiration date. The result: fewer support tickets, fewer oversights, and a reduced operational burden for IT teams that are often understaffed.
For healthcare providers: Simplify access without compromising security. Single sign-on (SSO) allows healthcare professionals to access all their line-of-business applications with a single login. Combined with multi-factor authentication (MFA) via a CPS card or e-CPS, it secures access while eliminating the need for multiple passwords. Healthcare providers spend less time logging in and more time at patients’ bedsides.
Compliance: Evidence is available at all times. Every access event is tracked, every authorization is documented, and every rights review is logged. In the event of an audit (HAS inspection, GDPR compliance review, HospiConnect requirements), the facility can produce a complete audit trail without having to reconstruct it manually.
Where to Start an IAM Project in a Healthcare Facility
An IAM project in the healthcare sector is not rolled out all at once. A phased approach is the most realistic, especially in multi-site organizations with heterogeneous information systems.
Map out user groups and data sourcesidentity. How many HR data sources feed into your accounts? Who are the users outside the HRIS (self-employed professionals, temporary workers, service providers)? What is the actual volume of active accounts, and how many are orphaned or generic accounts? This initial assessment is the foundation of any project.
Start with critical applications. The EHR is often the first target: it is the most sensitive application (health data), the most frequently audited, and the one that HospiConnect prioritizes. Connect Active Directory and the HRIS to an IAM platform, reconcile existing accounts, and transition from generic accounts to named accounts: this is the natural first phase.
Use the HospiConnect funding mechanism to finance the project. The HOP'EN 2 and CaRE funding allocations cover 2026, 2027, and 2028. A facility that does not utilize its 2026 allocation will forfeit that funding. The IAM project can be funded through these allocations, provided that the facility has submitted its project outline and aligned the project with the trajectory expected by the ANS.
Choose a tool suited to the hospital setting. Not all IAM solutions are equally suitable for a healthcare environment. Specific criteria include: the ability to manage populations outside the HRIS, connectors to hospital business applications (EHRs, prescription software), management of multiple contracts within hospital groups (GHTs), hosting that complies with healthcare data security requirements, and a French-language interface to facilitate adoption by non-technical teams. Youzer checks all these boxes: a sovereign IGA platform, hosted in France, designed to manage multi-source and multi-application environments. You can request a demo to see how it adapts to a hospital setting.
Identity management in healthcare facilities is not a luxury. It is a cybersecurity requirement in a sector where cyberattacks have a direct impact on patient care. It is also a compliance requirement, as regulations become stricter and audits become more frequent. HospiConnect funding offers a concrete opportunity to structure a project that many hospital CIOs have been putting off for years. The question is no longer whether to proceed, but where to start.





