It is 3am. A nurse on a rotational shift gets locked out of the EMR. The helpdesk opens in five hours. The patients on the floor do not wait five hours. So the nurse resets through a workaround, borrows a colleague's credential, or calls a charge nurse who was not scheduled to handle it. The shift continues. The identity event stays unresolved.
This is not a one-off. Multiply it by three shifts a day, 365 days a year, across a workforce of thousands, and the question stops being "how often does this happen" and starts being "what does it cost."
Healthcare does not operate like other industries. A typical physician carries dozens of active logins across the EMR, scheduling, e-prescribing, imaging, and affiliate systems. Affiliate clinicians, locum tenens, and contracted specialists move through the same identity stack as full-time employees, with weaker governance and less rigorous offboarding. The workforce presenting identity events is larger, more distributed, and more transient than in any other sector. And the hours when those events concentrate are the hours when the fewest people are available to handle them.
That operating reality is where the cost comes from. It shows up across four dimensions: workforce productivity, breach exposure, operational efficiency, and hiring fraud. In healthcare, three of the four are higher than in any other industry.
The Four Costs of Unverified Identity in Healthcare
The figures below are modeled for a 15,000-employee health system. They are drawn from Nametag's Cost of Doing Nothing report, with breach cost data sourced from IBM's 2025 Cost of a Data Breach Report.
Workforce Productivity: $1.86M annually
A 15,000-employee health system loses roughly 22,500 clinical hours each year to the verification queue. Not administrative hours. Clinical hours. That is the equivalent of 5,400 primary care visits the system already scheduled, already staffed, and lost to identity friction: credential resets, verification queues, and escalation handling spread across a rotational workforce.
The patients still need care. The institution still pays for the shift. The hours do not come back.
Breach Exposure: $4.97M annually
Every health system carries a financial exposure from identity-driven breach risk, whether or not a breach has occurred. In risk management, this is called Annual Loss Expectancy (ALE): breach probability multiplied by average breach cost. It is the number sitting on the books right now.
Healthcare's ALE sits at $4.97M at baseline. That figure is higher than any other sector. According to IBM's 2025 Cost of a Data Breach Report, healthcare averages $7.42M per breach and has led every other industry for 14 consecutive years. Breaches involving credentialed access to patient data take longer to detect, longer to contain, and produce broader compliance fallout than breaches anywhere else.
The $4.97M actuarial exposure does not wait for a breach to occur. It is carried on the books every day the risk remains open.
Operational Efficiency: $1.25M annually
Identity-related ticket volume at a 15,000-employee health system runs to roughly $1.25M in IT labor each year at a $25-per-ticket manual baseline. That cost does not stay flat. Every new hire, contractor, and affiliate added to the system adds to the ticket load. The helpdesk grows because the workforce grows, not because the verification process has improved.
Hiring Fraud: $1.24M annually (plus OFAC exposure)
A fraudulent hire in healthcare collects salary for a median of 122 days before anyone catches it. Four months of compensation paid to someone who should never have cleared the process, plus the recruiter labor spent investigating and the ramp and vacancy cost of replacing them.
Healthcare absorbs roughly $1.24M each year across those three cost buckets. OFAC sanctions liability is a separate exposure on top. A single hire who turns out to be a sanctioned individual carries strict liability under federal law, up to $26.7M per fraudulent placement.
The total annual cost adds up to $7.8M. That is roughly $150,000 every week the exposure stays open.
How the Change Healthcare Breach Made These Costs Real
In February 2024, Change Healthcare was breached. Pharmacy operations, claims processing, and clinical workflows across the U.S. healthcare system were disrupted for weeks. UnitedHealth Group reported the financial impact at $872M in the quarter following the attack.
The breach did not begin with a software exploit. It began with credentials on a Citrix portal that had no multi-factor authentication. Attackers operated inside the network for nine days before deploying ransomware.
Every cost dimension described above showed up at once. Clinical workflows stopped. The compliance fallout from credentialed access to patient data cascaded across providers. Operational capacity was consumed by incident response instead of patient care. The actuarial exposure that had been sitting on the books became a realized $872M loss.
The entry point was not a zero-day. It was a credential, used by someone no existing control was designed to verify.
That is the question the four cost dimensions above are measuring: what happens when no one confirms that the human behind the account is the person it belongs to.
What Identity Verification Changes for Health Systems
Authentication confirms a valid credential was presented. MFA confirms a device. Background checks confirm that records match a stated history. Each does what it was designed to do. None of them answers a different question: is the person presenting that credential the person it belongs to?
When that question gets answered at the moments that matter most in a health system, the cost structure shifts. The 3am recovery event, EMR access, affiliate credential issuance, and high-privilege approvals all resolve to the same question. And once the answer is verified, the numbers move.
The 22,500 clinical hours go back to the floor. The audit trail for every credentialed access event becomes defensible. IT ticket volume stops scaling with headcount. Hiring decisions include a layer of verification no background check was designed to provide. And the $150,000 that accumulates every week starts running in the other direction.
None of that requires replacing the identity stack already in place. It requires completing it.
For the full breakdown by cost dimension, including comparisons across six industries, read the Cost of Doing Nothing report.


