Replacing Interactive Authentication With Confirm ID Authentication

This topic only applies to your enterprise if your EMR application uses Imprivata ProveID Interactive Authentication to provide two-factor authentication.

As of January 1, 2019, Imprivata will no longer support ProveID Client Interactive Authentication. To continue to offer two-factor authentication, contact your EMR provider to determine if they support integration with Imprivata Enterprise Access Management with MFA (formerly Imprivata Confirm ID instead.

If your EMR software does not support integration, Enterprise Access Management with MFA provides a bridge from ProveID to Enterprise Access Management with MFA. This topic describes how this bridge works and how to enable your clinicians to use it.

Migration Assessment Tool

Go to this page at the Imprivata Customer Experience Center to download and run the Migration Assessment Tool. This tool will determine whether Interactive Authentication is in use in your environment, and report the next steps required.

How It Works

Your EMR application will not need to be reconfigured. When enabled, the Imprivata "ProveID Bridge" will receive legacy requests for Interactive Authentication from your EMR application and redirect them to Enterprise Access Management with MFA. Your clinicians will be prompted to authenticate via Enterprise Access Management with MFA instead of the legacy Imprivata ProveID authentication.

If you license other Imprivata ProveID or Enterprise Access Management with SSO features (for example, Single Sign-On or Self-Service Password Reset) they will not be affected. Only Interactive Authentication requests are redirected to Enterprise Access Management with MFA.

Requirements

  • Imprivata applianceImprivata Confirm ID 5.3 Service Pack 1 or later
  • Imprivata agentImprivata Confirm ID 5.3 Service Pack 1 or later. Any endpoints with an earlier agent will continue to use ProveID Interactive Authentication until it is no longer supported.

Configuration Overview

Configure your users and clinical workflows to support this integration with your EMR application.

  1. Select authentication methods for the following clinical workflows:
    • User verification (regulated)
    • Different user authentication
  2. For a seamless rollout to your clinicians, select the same authentication methods they're already using with Interactive Authentication.
  3. If you have added any new authentication methods, users must enroll those authentication methods.
  4. Move your providers into one or more user policies to be associated with these clinical workflows.
  5. Associate the providers' user policies with these workflows.
  6. The ProveID Bridge is enabled by computer policy. Enable the ProveID Bridge for some or all computer policies as needed: in the Imprivata Admin Console, go to ComputersComputer Policies and select a computer policy.
  7. On the General tab, select Use Confirm ID for Clinical Workflows instead of ProveID for interactive authentication.
  8. There is no Save button. The ProveID Bridge goes live as soon as you click the checkbox.