Epic EHR delivered via Citrix to Windows Workstations

This configuration is used in settings where there is direct interaction between the patient and the provider. It gives users fast access to the workstation and the Epic EHR:

  • The EHR is not closed on user switch.

  • Other applications, such as web browsers and email, are closed on user switch.

This topic details how each component in the following environment is configured.

Click to enlarge.

In this workflow, the Epic EHR (Epic) is delivered to a shared Windows workstations via Citrix DaaS application virtualization. For a summary of this architecture and Imprivata license requirements, see Epic EHR delivered via Citrix to Windows Workstations.

Imprivata Enterprise Access Management Configuration

In this section you configure the Imprivata user and computers policies:

  • An Imprivata user policy is the means by which you define authentication methods and rules to a specific group of users.

  • An Imprivata computer policy is the means by which you define security parameters to a specific set of workstations.

    This workflow requires two computer policies. The first policy is assigned to the shared workstations, while the second policy is assigned to the Citrix servers that are delivering Epic.

NOTE:

The following steps detail the required settings to achieve this workflow. For complete details on user and computer policies, see the Imprivata Enterprise Access Management Help.

Citrix Server Configuration

In this section, you install the Imprivata agent and the Imprivata Connector for Epic Hyperdrive on the Citrix servers that are delivering Epic.

  • Installing the Imprivata agent on the Citrix Servers enables Imprivata to communicate between Citrix environment and the shared workstations.

  • Installing the Imprivata Connector for Epic Hyperdrive enables Fast User Switching for Epic Hyperdrive.

Shared Windows Workstations Configuration

In this section, you configure your shared workstations to automatically boot and authenticate to Window generic workstation–based credentials:

  • The generic credentials are only used to log into the workstation.

  • Citrix Workspace app uses the generic credentials to connect to Citrix and deliver the hosted Epic EHR.

  • When the Imprivata agent detects the user switch, the Imprivata user is logged into the Epic EHR.

 

Epic EMR Configuration

In this section, you configure the Imprivata Connector for Epic Hyperdrive.