Identity Management in Healthcare: Why Healthcare Organizations Can No Longer Do Without It

Published :

August 2026

| Updated on

-
Articles
>
Compliance
A university hospital with 10,000 employees can record 2,500 account changes in a single summer. This includes account creations, suspensions, changes to access rights, and temporary accounts for July substitutes. On this scale, manually managing IT identities and access is no longer feasible. And yet, many healthcare facilities still operate without a structured Identity and Access Management (IAM) solution. The consequences are measured in orphaned accounts, unrevoiced access, and non-compliance issues that quietly accumulate.

Summary

What is IAM as it applies to the healthcare sector?

IAM (Identity and Access Management) refers to the set of processes and tools used to manage who has access to what within an information system. In healthcare facilities, this issue takes on a special significance.

A hospital is not a typical business. Healthcare staff work 24/7, with positions shared among several employees. Staff profiles vary widely: salaried physicians, private practitioners, temporary staff, part-time workers, external service providers, and administrative personnel. Some work at multiple sites within the same Regional Hospital Group (GHT), with different roles depending on the facility. A surgeon, for example, might hold a management role at one hospital and a clinical role at another.

Line-of-business applications are also specialized: EHR (Electronic Health Record), prescription software, bed management systems, imaging, laboratory, and patient administrative management (PAM). Each has its own access rights and authorization levels. These tools are rarely interconnected: PAM does not communicate with the EHR, and the EHR does not communicate with bed management. Each application operates in a silo, with its own accounts, its own passwords, and no overall view. The HOP'EN 2 program confirms this: the fragmentation of hospital information systems is identified as a structural barrier to the quality and safety of care.

IAM in healthcare is the building block that ties it all together: a single identity repository, connected to HR systems, that centralizes all of the institution’s applications and links application accounts to their users. One healthcare provider, one identity, consistent access rights across all applications.

The Practical Problems That Arise When a Facility Does Not Have an IAM

The risks associated with not having an IAM are not merely theoretical. They occur on a daily basis in organizations that manage their accounts manually.

Accounts that no one deactivates. Organizations with high turnover automatically accumulate active user accounts belonging to employees who have left. This phenomenon is observed in hospitals, as well as in staffing agencies and fire and rescue services: the more frequent staff turnover is, the more orphaned accounts pile up if there is no automated process to deactivate them. In a context where cyberattacks against hospitals are on the rise, every orphaned account is a potential entry point. In February 2021, a ransomware attack on the Dax Hospital Center took the entire information system offline for several weeks. According to ANSSI’s analysis, the attackers gained access to the facility’s directory and acquired domain administrator rights within a few hours, which allowed them to deploy the ransomware on multiple servers simultaneously.

Generic accounts that prevent any traceability. Four nurses sharing the same “nursing station” username in the EHR: this is still a reality in many facilities. It’s impossible to know who accessed which patient record, impossible to conduct a thorough audit, and impossible to comply with the GDPR. The goal of traceability for access to health data becomes a pipe dream.

Entire groups of people fall off the radar. Private practitioners, physical therapists, and temporary staff do not go through the standard HRIS system. Their arrival is not always reported to the IT department, and their departure even less so. These “non-HRIS” groups sometimes account for 20 to 30 percent of users of the information system in clinics and medical-social facilities.

Siloed applications with no common repository. EPR, GAP, bed management, imaging, lab results, and prescribing software: each application has its own user directory, its own access rules, and its own account creation processes. When a healthcare professional joins the team, the IT department must manually set up their access in each system. When they leave, the IT team has to remember to revoke access one by one. Without a centralized identity repository, inconsistencies multiply, and the IT department loses visibility into who has access to what.

Unmanageable access reviews. Compliance requires regularly verifying that each user has access only to what they need. Without a centralized tool, this review must be conducted application by application and department by department. For IT teams that are already understaffed, this is a colossal task, one that is often postponed or done halfheartedly.

Fragmented governance across multiple sites. In healthcare and social services groups or hospital groups (GHTs), each facility has its own practices, its own IT administrators, and sometimes its own directories. The central IT department lacks a consolidated view of all accounts and access rights. Authorization rules vary from one site to another without any consistency.

Here is what the IAM actually does in a school:

Hospital Situation Without IAM With an IAM solution
Arrival of a healthcare worker Manual creation of accounts in each application, a process that takes several days, and the risk of overlooking accounts Automatic provisioning triggered by an HRIS event: accounts are created across all applications in just a few minutes
Start or End of Assignment Forgotten or delayed deactivation, orphan accounts piling up Automatic suspension of access rights as of the contract end date, without manual intervention
Internal Mobility Existing rights retained + new rights added, with a phased expansion of authority Permissions automatically recalculated based on the new role; previous permissions revoked
Temporary Workers and Freelancers (excluding HRIS) Accounts created "on the fly" without a paper trail, sometimes never deleted Submission via form, approval process, automatic expiration date
Isolated business applications Each application (DPI, GAP, imaging) manages its accounts separately; there is no consolidated view Centralized identity repository that feeds all applications; automatic account reconciliation
Review of Authorizations A manual process, carried out on a per-application basis, rarely completed Centralized magazine campaigns, with a validation workflow managed by supervisors
Access to the DPI Shared generic accounts, no individual traceability Personal accounts, single sign-on (SSO), full access tracking
Audit or Compliance Review Time-consuming process of reconstructing access paths, scattered data Consolidated history, exportable audit trail, immediate proof of compliance

What Regulations Now Require of Institutions

The HospiConnect program, led by the French Digital Health Agency (ANS) as part of HOP'EN 2 and the CaRE program, requires healthcare facilities to follow a clear path for identity management. Four operational requirements form the framework of the program: registering all healthcare professionals in a local directory compliant with the RPPS, implementing an IAM module to manage access permissions and the account lifecycle, deploying strong authentication (SSO, MFA), and connecting to Pro Santé Connect for access to the DMP.

The deadlines have been set. The framework document was to be submitted by June 26, 2026. The first technical requirements for doctors and nurses take effect in June 2027. Full implementation for all EHR users is scheduled for June 2028.

But HospiConnect isn’t the only framework. The HOP’EN 2 program also includes a “call for proposals” component that funds projects aimed at closing the digital maturity gap and improving time management and HR processes—two areas that directly intersect with identity management. Here is an overview of the requirements and funding:

Regulations / Program What it requires in terms of identity management Due Date Funding Available
HospiConnect (ANS / HOP'EN 2) RPPS Reference Framework, IAM Component, SSO/MFA, Pro Santé Connect Integration June 2027 (physicians, registered nurses), followed by June 2028 (full implementation) Yes: HOP'EN 2 + CaRE funding packages, multi-year 2026–2028. Funding caps ranging from €35,000 (Category A) to €205,000 (Category D) per project, depending on the combined activity
HOP'EN 2 — Call for Proposals Catching up on digital maturity (including DPI and identity monitoring), time management, and HR processes (reliable organizational framework) 2026 Applications, 2026–2028 Funding Yes: 87.2 million euros allocated to regional budgets. 50% paid upon acceptance, 50% upon achievement of objectives
PGSSI-S Strong authentication, access rights management, and traceability of access to health data In effect (ongoing framework) No (no dedicated funding)
GDPR Access to personal data limited to what is strictly necessary, traceability, right of access and rectification In effect since 2018 No
NIS 2 (European Directive) Access Management, Least Privilege, Incident Response Capabilities, Security Governance Transposition in progress No (no specific funding for health care)

The key point for a hospital CIO: HospiConnect and HOP'EN 2 are currently the only frameworks that come with funding. This presents a window of opportunity to launch an IAM project that meets all requirements at once—not just those of HospiConnect.

How IAM Is Transforming the Day-to-Day Work of IT Teams and Healthcare Providers

The value of an IAM solution goes beyond simply checking off regulatory requirements. Its impact is felt on a daily basis, both by IT teams and by healthcare professionals.

From the CIO’s Perspective: Regaining Control of the Lifecycle. Automated provisioning is a game-changer. An event in the HRIS (hiring, transfer, departure) automatically triggers the creation, modification, or suspension of accounts across all connected applications. Youzer, for example, automates this lifecycle by connecting to the organization’s HR data sources, including for personnel outside the HRIS (private practitioners, temporary staff) who are registered via forms with an approval workflow and expiration date. The result: fewer support tickets, fewer oversights, and a reduced operational burden for IT teams that are often understaffed.

For healthcare providers: Simplify access without compromising security. Single sign-on (SSO) allows healthcare professionals to access all their line-of-business applications with a single login. Combined with multi-factor authentication (MFA) via a CPS card or e-CPS, it secures access while eliminating the need for multiple passwords. Healthcare providers spend less time logging in and more time at patients’ bedsides.

Compliance: Evidence is available at all times. Every access event is tracked, every authorization is documented, and every rights review is logged. In the event of an audit (HAS inspection, GDPR compliance review, HospiConnect requirements), the facility can produce a complete audit trail without having to reconstruct it manually.

Where to Start an IAM Project in a Healthcare Facility

An IAM project in the healthcare sector is not rolled out all at once. A phased approach is the most realistic, especially in multi-site organizations with heterogeneous information systems.

Map out user groups and data sourcesidentity. How many HR data sources feed into your accounts? Who are the users outside the HRIS (self-employed professionals, temporary workers, service providers)? What is the actual volume of active accounts, and how many are orphaned or generic accounts? This initial assessment is the foundation of any project.

Start with critical applications. The EHR is often the first target: it is the most sensitive application (health data), the most frequently audited, and the one that HospiConnect prioritizes. Connect Active Directory and the HRIS to an IAM platform, reconcile existing accounts, and transition from generic accounts to named accounts: this is the natural first phase.

Use the HospiConnect funding mechanism to finance the project. The HOP'EN 2 and CaRE funding allocations cover 2026, 2027, and 2028. A facility that does not utilize its 2026 allocation will forfeit that funding. The IAM project can be funded through these allocations, provided that the facility has submitted its project outline and aligned the project with the trajectory expected by the ANS.

Choose a tool suited to the hospital setting. Not all IAM solutions are equally suitable for a healthcare environment. Specific criteria include: the ability to manage populations outside the HRIS, connectors to hospital business applications (EHRs, prescription software), management of multiple contracts within hospital groups (GHTs), hosting that complies with healthcare data security requirements, and a French-language interface to facilitate adoption by non-technical teams. Youzer checks all these boxes: a sovereign IGA platform, hosted in France, designed to manage multi-source and multi-application environments. You can request a demo to see how it adapts to a hospital setting.

Identity management in healthcare facilities is not a luxury. It is a cybersecurity requirement in a sector where cyberattacks have a direct impact on patient care. It is also a compliance requirement, as regulations become stricter and audits become more frequent. HospiConnect funding offers a concrete opportunity to structure a project that many hospital CIOs have been putting off for years. The question is no longer whether to proceed, but where to start.

Need to estimate the cost of an IAM project?

Download this white paper on the cost of inaction in IAM :

We have been unable to confirm your request.
Your request for a white paper has been taken into account.

Recommended Articles