Roaming Epic EHR Delivered via Application Virtualization to Windows Workstations

This configuration can be used in most clinical settings:

  • A shared workstation with roaming applications lets users move from workstation to workstation and automatically connect to one or more applications, including the Epic EHR (Epic).
  • As users authenticate to different shared workstations, they reconnect to their virtualization session, which makes it appear as if their applications are "roaming" with them.
NOTE:

This configuration is not recommended for settings where patient medical records must remain persistent on the workstation for different users to access. For example — an exam room.

This topic details how each component in the following environment is configured.

Click to enlarge.

In this workflow, the Epic EHR (Epic) is delivered to a shared Windows workstations via Citrix DaaS application virtualization. For a summary of this architecture and Imprivata license requirements, see Epic EHR Delivered via Citrix to Windows Workstations.

Imprivata Enterprise Access Management Configuration

In this section you configure the Imprivata user and computers policies:

  • An Imprivata user policy is the means by which you define authentication methods and rules to a specific group of users.

  • An Imprivata computer policy is the means by which you define security parameters to a specific set of workstations. This workflow requires two computer policies:

    • The first policy is assigned to the shared windows workstations.

    • The second policy is assigned to the Citrix servers that are delivering Epic.

NOTE:

The following steps detail the required settings to achieve this workflow. For complete details on user and computer policies, see the Imprivata Enterprise Access Management Help.

Shared Windows Workstations Configuration

In this section, you configure your shared workstations to automatically boot and authenticate to Windows with generic workstation–based credentials:

  • The generic credentials are only used to log into the workstation.

  • When the Imprivata agent detects the user switch, the Imprivata user is logged into the Epic EHR.

Citrix Server Configuration

In this section, you install the Imprivata agent and the Imprivata Connector for Epic Hyperdrive on the Citrix servers that are delivering the Epic EHR.

  • Installing the Imprivata agent on the Citrix Servers enables Imprivata to communicate between Citrix environment and the private workstations.

  • Installing the Imprivata Connector for Epic Hyperdrive enables access to Epic Hyperdrive.

Epic Configuration

In this section, you configure the Imprivata Connector for Epic Hyperdrive.