Configuring Epic Only Virtual Kiosks for Citrix XenApp

Introduction

In this workflow, multiple users share an Imprivata ProveID Embedded workstation (thin client) to use the Epic EHR (Epic) under the correct credentials.

  • The Epic EHR (Epic) is delivered to the thin client via Citrix Virtual Apps application virtualization.

    Epic is the only application that is available on the thin client. This configuration is known as Epic Only mode.

  • The thin client establishes a Citrix session using generic user credentials.

    While Epic remains running under the generic user credentials, users authenticate to the Imprivata Connector for Epic Hyperdrive (Connector), and work under their credentials.

  • When the Connector detects a user switch, Imprivata OneSign keeps Epic open, while switching the user that is logged in.

Before You Begin

Clinical Workflow and Citrix License Usage

A Citrix license is consumed when the thin client establishes a Citrix session and launches the resource. The procedures in this guide detail how to configure the computer policy to determine when the thin client establishes the session, thereby controlling license usage, but affecting the end user workflow.

You can configure the computer policy to enforce one of the following:

  • Automatically reconnect to a session when a session ends.

  • Wait for a user to manually start a session.

The Automatically reconnect on session end setting, which is located on the Shared Workstation tab of the computer policy, controls this behavior. Review the following and identify which workflow best fits the needs of your organization. Use this information when configuring the computer policy.

Thin Client Configuration

In this section, you configure your thin clients to automatically connect to the published Epic application with generic workstation–based credentials.

Citrix Configuration

In this section, you install the Imprivata agent and the Imprivata Connector for Epic Hyperdrive on the Citrix servers that are delivering Epic.

  • Installing the Imprivata agent on the Citrix Servers enables Imprivata to communicate between Citrix environment and the shared workstations.

  • Installing the Imprivata Connector for Epic Hyperdrive enables fast user switching.

Imprivata OneSign Configuration

In this section you configure:

  • A user policy.

  • Two computer policies.

    One for your thin client workstations, and another for the Citrix server that is delivering the published desktop.