Imprivata Digital Identity Solutions Overview and Architecture

The Imprivata Digital Identity Framework (DIF) provides an organized structure to help healthcare delivery organizations holistically manage, secure, and monitor their organization’s digital identities. The framework is designed around the key categories required for a robust digital identity strategy that meets the unique demands of healthcare. These categories, which align with H-ISAC’s identity framework for healthcare, include the following: governance and administration, identity management, authorization, and authentication and access.

The Imprivata DIF is represented in the diagram and includes a color-coded legend that describes how Imprivata’s digital identity solutions map to each of the capabilities defined in the framework. This guide will focus on reference architectures for implementing Imprivata Enterprise Access Management single sign-on, multifactor and advanced authentication using Imprivata Confirm ID , and mobile solutions using Imprivata Mobile Access Management (GroundControl) to support workflows with Epic EHR and Epic Rover.

The Imprivata Digital Identity Framework. Click to enlarge.

Imprivata Enterprise Access Management SSO and MFA Overview

Imprivata Enterprise Access Management for SSO is the enterprise single sign-on (SSO), authentication management (AM), virtual desktop access (VDA), and self-service password reset (SSPR) solution specifically designed for healthcare. Enterprise Access Management provides simple and secure access to both cloud and on-premises clinical and administrative applications enabling providers to instantly log into their desktop and sign into their applications with just a tap of a badge or swipe of a finger. Enterprise Access Management security also helps to protect patient data, empowering organizations to meet HIPAA compliance requirements, preventing credential-sharing, securing PHI on unattended workstations, and enabling easier and more thorough auditing and reporting of workstation and application access.

Imprivata Enterprise Access Management for MFA is a comprehensive identity and multifactor authentication solution designed for healthcare. Enterprise Access Management centralizes identity and multifactor authentication across all enterprise workflows, including remote access, cloud applications, Electronic Prescribing of Controlled Substances (EPCS), medical devices, and clinical workflows such as medical ordering, witness signing, user verification, and procedure attestation. Enterprise Access Management also supports a variety of authentication methods, including hands-free authentication, push token, fingerprint, badge, SMS, and more. Users are only prompted for those authentication methods for which they are enrolled and that are available and allowed for the specific workflow.

The sections below describe the Imprivata appliance and Imprivata agent — the key components of the Imprivata architecture — as well as design considerations for implementing SSO and MFA with the Epic EHR.

Imprivata Enterprise Design

An Imprivata enterprise consists of at least two Imprivata appliances that service authentication requests from a collection of Imprivata agents. The appliances are configured to connect to existing IT infrastructure including:

  • AD domain controllers

  • DNS servers, NTP servers, SMTP servers for alerts

  • FTP servers or file shares for storing backups, offloading archived audit data, and storing reports

The connections between the Imprivata agents and the Imprivata appliances use the secure ISX protocol.

Imprivata recommends deploying at minimum a single appliance in each of two data centers to provide data center-level redundancy. In this configuration, the data stored within each appliance in the two data centers is replicated to the peer appliance in the alternate data center. Imprivata agent connect to the appropriate appliance based on site configuration and appliance availability.

Imprivata Mobile Access Management Overview

Imprivata Mobile Access Management (formerly GroundControl) delivers automated setup and check-in / check-out workflows for shared mobile devices. The solution helps optimize the workflows for users of mobile devices while improving security and auditability. When used in conjunction with Imprivata Enterprise Access Management, MAM provides proximity card-based device check out and credential autofill for mobile applications, which further streamlines mobile workflows.

The sections below describe the key components of Imprivata Mobile Access Management including the cloud tenant and associated management console, the Launchpad, smart hubs, mobile devices, mobile device management (MDM), and the Locker mobile application. Design considerations for implementing MAM with Epic Rover are also provided.

Imprivata Mobile Access Management logical architecture. Click thumbnail to enlarge.