Hands Free Authentication for Imprivata Confirm ID

This topic provides an overview of Hands Free Authentication for Imprivata Confirm ID and what you need to deploy it in your enterprise and roll it out to users.

Overview

Hands Free Authentication automatically and securely retrieves a one-time password (OTP) from the provider's device to authenticate when signing electronic prescription orders. The OTP, which is generated every 30 seconds by the Imprivata ID app, is validated over an encrypted, low-energy Bluetooth connection between the endpoint computer and the provider's device. This workflow results in minimal disruption to the clinical workflow, as the provider does not have to touch or handle the device.

The Imprivata ID app can be downloaded from Google Play and the iTunes App Store.

Notes:

  • Hands Free Authentication can only be used as a second factor of authentication.
  • Hands Free Authentication is not currently allowed by the Ohio State Board of Pharmacy for non-EPCS workflows.

Getting Started

For specific configuration steps related to the sections below, first see Planning an Imprivata Confirm ID Implementation, and then see Installing and Configuring Imprivata Confirm ID.

Certificate Requirements

If the Symantec token is embedded in Imprivata ID, and your users will be using Imprivata ID for Hands Free Authentication, your enterprise requires the following certificates be uploaded to the enterprise:

Endpoint Computer Requirements

For the complete list of supported devices, see Imprivata Confirm ID Supported Components.

Hands Free Authentication for Imprivata Confirm ID is currently supported on Teradici PCoIP® Zero Clients via VMware Horizon View virtual desktops. Teradici PCoIP® Zero Clients automatically recognize the Imprivata USB Receiver via the device's native USB redirection support. However, by default USB redirection on VMware Horizon View virtual desktops is disabled.

An Imprivata ID USB Receiver must be connected to each endpoint computer on which Imprivata ID Hands Free Authentication will take place. The Imprivata ID USB Receiver is not required when a provider enrolls Imprivata ID.

IMPORTANT: Make sure the Imprivata ID USB Receiver is not located in a metal enclosure and is located in close proximity to where providers will sign orders.

Provider Requirements

All providers using Hands Free Authentication must have an iOS or Android device with the following:

iOS Requirements

  • iOS 11 or later installed.

  • An active Internet connection is required to enroll Imprivata ID, as well as to send log files to Imprivata.

  • Hands Free Authentication:

    • Bluetooth enabled.
    • Access to Location Services (Always).
    • An active Internet connection is not required for Hands Free Authentication or manual token code entry.
  • Remote Access:

    • Notifications enabled.
    • An active Internet connection is required for push notifications.
  • Secure Walk Away

    • iPhone 6s or later.

    • Access to Location Services (Always), Bluetooth Sharing, and Motion & Fitness is required.

  • QR code for direct access to the download page on the iTunes App Store:

Android Requirements

  • Android 6 or later installed.

  • An active Internet connection is required to enroll Imprivata ID, as well as to send log files to Imprivata.

  • Hands Free Authentication:

    • Bluetooth enabled.
    • An active Internet connection is not required for Hands Free Authentication or manual token code entry.

  • Remote Access:

    • Notifications enabled.

    • An active Internet connection is required for push notifications.

  • Secure Walk Away:

    • Samsung Galaxy S7 or later.

    • Google Pixel 1 or later.

    • OnePlus 6 or later.

    • Bluetooth enabled.

  • QR code for direct access to the download page on Google Play:

Identity Proofing Requirements

If you have providers who are configured in the Imprivata Admin Console as Individual providers (they may not prescribe using your institution's DEA number), then you need to configure Imprivata Confirm ID to enable identity proofing.

Imprivata ID For Administrators with Multiple Usernames

One Imprivata ID can be enrolled to multiple usernames. Administrators can authenticate to more than one account with the same Imprivata ID token:

  1. In the Imprivata Admin Console, go to the gear icon > Settings.

  2. In the section Imprivata ID, select Allow one Imprivata ID token for multiple accounts.

  3. Click Save. An Imprivata ID can now be enrolled to more than one Imprivata username. There is no restriction by role; any Imprivata ID can now be enrolled again to any Imprivata user (if their user policy permits Imprivata ID enrollment).

End Of Life: Imprivata ID Symantec Token (IMSY)

The ability to enroll Imprivata ID with an IMSY token has been removed.

All phones already enrolled with Imprivata ID and the IMSY token will still work, but when those users replace their phone and/or reinstall Imprivata ID, they will receive the IMPR token instead.

Symantec VIP tokens are not affected.

Rolling Out Hands Free Authentication to Users

Like other Imprivata Confirm ID authentication methods, providers must enroll their Imprivata ID:

  • The Imprivata ID app can be enrolled using the Imprivata Confirm ID enrollment utility. Depending on how you configure Imprivata Confirm ID, supervised enrollment may be required.
  • You can allow Imprivata Confirm ID Remote Access users to enroll the Imprivata ID app remotely.

Imprivata recommends that enrollment supervisors and Imprivata ID users receive training about Hands Free Authentication to ensure seamless adoption in your organization.

The following educational materials can be used to train enrollment supervisors and Imprivata ID users about Hands Free Authentication; they can be downloaded via the Imprivata ID User Rollout Kit [ZIP].

Document Audience Description Format
Introducing Hands Free Authentication (HTML Email Template)
  • Enrollment supervisors
  • Providers

Customizable HTML email template you can use to announce Hands Free Authentication support to providers in your organization; includes a link for downloading the Imprivata ID app and instructions on how to enroll their Imprivata IDs.

How to use this template:

  1. Download the file and open it in a text editor. Make the indicated customizations and save your changes.

  2. Copy the contents of the HTML file and paste them into a new, blank email.

.HTML
Introducing Imprivata ID for Remote Access (HTML Email Template)
  • Enrollment supervisors
  • Providers

Customizable HTML email template you can use to announce Remote Access support to users in your organization; includes a link for downloading the Imprivata ID app and instructions on how to enroll their Imprivata IDs.

How to use this template:

  1. Download the file and open it in a text editor. Make the indicated customizations and save your changes.

  2. Copy the contents of the HTML file and paste them into a new, blank email.

.HTML
Imprivata Confirm ID Enrollment Guide for Supervisors Enrollment supervisors Instructions for witnessing and attesting to provider enrollment of Imprivata IDs, OTP tokens, and fingerprints for e-prescribing controlled substances. .PDF
How to Enroll Your Imprivata ID Institutional providers Instructions for Institutional providers (providers who have been identity proofed by hospital staff) on how to enroll their Imprivata ID. .PDF
How to Complete Identity Proofing and Enroll Your Imprivata ID Individual providers Instruction for Individual providers (providers who cannot use an institution's DEA number) on how to complete identity proofing and enroll their Imprivata ID for Hands Free Authentication. .PDF
Imprivata ID Phone Readiness Checklist Providers Visual overview of the optimal configuration for Imprivata ID. Intended to be distributed to providers for training and/or posted at workstations. .PDF

Troubleshooting