Imprivata is a healthcare-focused IT security company headquartered in Lexington, Massachusetts, with a UK office, founded in 2002. It delivers authentication and access management solutions with strong emphasis on healthcare workflows and regulatory requirements. The company has over 450 employees, works with about 200 reseller partners, and serves more than 1,700 healthcare customers representing over 5 million users worldwide. KuppingerCole recognized Imprivata OneSign as an overall leader in Enterprise Single Sign-On, and Imprivata expanded into Identity Governance and Administration (IGA) through acquiring Caradigm’s IAM product line.
Healthcare presents distinctive IAM challenges: highly sensitive, regulated data; high turnover among clinical workers; complex and frequently changing role structures; and reliance on diverse healthcare-specific cyber-physical systems. Clinicians often need rapid access to multiple standalone systems across locations, each with different authentication requirements. Imprivata’s portfolio targets business-to-employee SSO and IGA with a goal of improving clinician efficiency, with many products delivered as Windows-based appliances and aligned to HIPAA, HITECH, and DEA requirements for strong authentication in electronic prescribing.
Imprivata Identity Governance integrates identity provisioning and access governance. Automated role-based provisioning supports onboarding, role changes, and offboarding; a cited merger case study reports major reductions in administrative labor and time to create accounts. A Provisioning Solutions Assessment service uses a half-day workshop with caregivers, IT, compliance, HR, and application specialists to design an automated provisioning model. Integration is addressed through a connector library (e.g., Epic, Cerner, GE, McKesson) and Bridge Studio, a graphical tool for configuring provisioning attributes and conditional workflows. Governance is provided via a GRC Executive Dashboard offering role-based visibility, remediation actions, analytics combining entitlements with actual access activity, and reporting plus certification workflows. Strengths include healthcare fit, connectors, and scalable RBAC provisioning; challenges include product-line rationalization and lack of federation and privileged account management, with no SIEM integration or risk analytics.
See All Locations
See All Locations