Authentication (IT)
Published on: 12th July 2017 | Updated on: 21st July 2026
Authentication and access controls help protect patient information by ensuring only authorised people can access systems and data. Authentication is also used to verify the identity of patients when they access NHS digital services.
As community pharmacy becomes increasingly digital, strong authentication methods are essential for protecting patient data, meeting cyber security requirements, and supporting safe access to NHS systems.
The most common authentication methods used in health and care systems are outlined below.
| Authentication methods/systems | Notes |
| Biometrics | E.g. fingerprint technology, face ID and voice recognition. |
| CAPTCHA |
This authentication method intends to distinguish whether a webform or similar online item is being completed by a real person or an automated ‘bot’. A CAPTCHA might require an extra ‘click’ or a ‘tap’ by a person completing a webform, or it might require clicking on images or identifying letters and numbers from within an image. CAPTCHA stands for: “Completely Automated Public Turing test to tell Computers and Humans Apart”. CAPTCHAs can be used on webforms to reduce automated spam being submitted. Automated spam submissions could include links to bad webpages being used with the purpose of phishing or distribution of viruses. |
| Digital signatures | Signatures (if required) may be provided digitally by pharmacy teams or by patients e.g. by finger tips onto a mobile device screen – supporting the paperless goals. |
| Identifiers | Some systems may authenticate you at least partially using common identifiers e.g. your Smartcard number of GPhC number if you have one. |
| Identity Agent | A component sitting on pharmacy computers, that facilitates use of Smartcards or NHS authentication. |
| Login with NHSmail | Some NHSmail systems may provide a ‘login with NHSmail’ option. |
| Care Identity Service 2 (CIS2) |
CIS2 is an authentication system being piloted that provides a small number of health and care professionals in England to prove their identity when accessing national clinical information systems e.g. Summary Care Record (SCR). Authentication is either via:
CIS2 will continue to be expanded and other developers such as Patient Medication Record (PMR) system providers or website developers may consider integrating with it in the future. |
| NHS Credentials Management | NHS Credential Management is a component and standalone installation sitting on pharmacy computers, that facilitates communication between the Identity Agent software and modern browsers to support use of Smartcards or NHS authentication. |
| NHS login | NHS Digital developed a single system for verifying the identity of those patients requesting access to digital health records and services (used within NHS App for example) |
| Multi-factor or two-factor authentication (MFA/2FA) – | Involves demonstration of: knowledge (something you know), possession (something you have), and inherence (something you are). Such methods provide additional protection compared with a username/password system. |
| Passwords |
Standard authentication method. The National Cyber Security Centre (NCSC) now recommend organisations do not force regular password expiry because that may create vulnerabilities and do little to reduce the risk of password exploitation. Read more: NCSC password guidance. Top tip: NCSC recommend that a strong and memorable password is created by choosing three random words, e.g. ‘planeyellowbread’. |
| Role-based access control (RBAC) | RBAC within the pharmacy can control what a pharmacy team member can do and what they can see. |
| Single sign-on (SSO) | SSO is an authentication method that allows users to sign in once using a single set of credentials and securely access multiple websites or applications without needing to log in again. In healthcare and pharmacy settings, SSO can improve security, reduce password fatigue, and make it quicker for pharmacy teams to access the digital services they use every day. |
| Smartcards | Provide security measures to protect patient data. |
NHS authentication standards
Relevant NHS standards include:
- Identity authentication standards (NHS England guidance).
What is multi-factor authentication?
Multi-factor authentication (MFA) adds extra verification steps when users sign in to a system.
For example, after entering a password, a user might also need to:
- Enter a code sent to their phone or email;
- Approve a sign-in using an authenticator app;
- Answer a security question; or
- Use biometric verification such as a fingerprint.
Many people already use MFA when accessing online banking, shopping websites or social media accounts.
Using more than a username and password significantly reduces the risk of unauthorised access to systems and data.
Why is MFA important?
As a pharmacy owner, you should consider whether MFA is appropriate for your systems.
To meet the Data Security and Protection Toolkit (DSPTK) requirements, pharmacy owners may need to demonstrate they have considered MFA and documented any exceptions where it has not been implemented.
Steps to introduce MFA
Review your current systems
Identify systems that can be accessed via the internet, such as:
- Email services;
- Cloud-based systems; and
- Digital patient record systems.
Check available guidance from your software provider or IT supplier.
Identify potential challenges
Consider whether:
- Team members share devices;
- Existing authentication arrangements may affect MFA deployment; or
- Alternative security controls already provide adequate protection.
Balance security and usability
Consider:
- The sensitivity of the information being accessed;
- The risks associated with the system; and
- The impact on pharmacy workflows.
Security measures should be proportionate and practical.
Document exceptions
If you decide not to implement MFA for a particular system:
- Record the decision;
- Document the reasons; and
- Understand and document the risks.
Keep authentication practical
Strong security is important, but pharmacy teams also need efficient access to systems.
Aim to improve security while avoiding unnecessary login burden or processes that encourage workarounds.
Overview
Passwords should not be reused across multiple systems. If one account is compromised, reused passwords can put other accounts at risk.
The National Cyber Security Centre recommends creating strong and memorable passwords using three random words.
For example:
planeyellowbread
Some systems may require additional complexity, such as:
- Capital letters;
- Numbers; or
- Special characters.
Routine password changes are generally not required unless there is a specific security concern or system requirement.
Password and access control procedures
See:
DSPTK Template 15: Access control and password management procedures
Additional templates are available at:
Password tips
- Use three random words where possible;
- Avoid common passwords such as “123456”, “qwerty”, “asdfg” or “111111”;
- Avoid using personal information, such as birthdays, names or favourite sports teams;
- Use a different password for each account;
- Be aware of people nearby when entering passwords;
- Use of others devices: Avoid signing in on devices you do not control;
- Public WiFi: Avoid entering passwords when connected to unsecured public Wi-Fi;
- Never share your password with other people; and
- Password storage: If you write passwords down, store them securely and separately from your device.
- Password managers: NCSC support people and businesses using suitably reputable and secure password manager solutions
Community Pharmacy IT Group (CP ITG) supports authentication methods that improve security while reducing unnecessary login burden for pharmacy teams. This includes approaches such as:
- Login with nhs.net;
- Care Identity Service 2 (CIS2);
- Biometrics; and
- Future NHS single sign-on approaches.
Password managers may also be suitable for some systems. The National Cyber Security Centre provides guidance on the safe use of password managers.
Community Pharmacy England and CP ITG continue to support improvements that reduce the number of separate logins required across pharmacy systems and NHS services. This aligns with wider NHS ambitions to simplify authentication and reduce administrative burden for frontline teams.
Pharmacy teams have reported that accessing multiple systems throughout the day can create significant login burden. CP ITG has previously highlighted this issue through its work examining the range of systems used across community pharmacy.
For more information on this topic please email it@cpe.org.uk












