
NoPass™
Passwordless workforce access and approval checkpoints for sensitive actions in your applications.
Explore NoPassSolutions / Healthcare
Patients need to recognize the organization asking them to act. Care teams need access that fits their work. Mutual authentication brings both sides into that relationship.

A patient receives a prompt to open a portal. A clinician returns to a workstation between tasks. Familiar names and repeated sign-ins can make it easy to act before considering who is asking.
FDA establishes a relationship between the connected service and enrolled app. The app checks the authentication server, and the person compares the visible request before approving. A patient can participate in checking the institution as the institution authenticates the patient.
Consider a patient portal that asks the account holder to authorize release of a personal health record. The portal can be integrated with a NoPass™ approval checkpoint: hold the release, request device confirmation and apply the person’s response.
The portal retains its consent and access rules. Its integration determines where this confirmation belongs before confidential information is released.
Record-release approval · interactive example
The application sends a NoPass approval request to the person responsible. Start the request in the application.
Open the push notification on the enrolled phone. The application waits while you check the request.
Release a health record
Compare the black picture and number. If this is the request you intended, select Confirm on the phone, using the local confirmation configured for your device, such as fingerprint or Face ID.
Compare this picture and number with your phone.
501Do you approve this record release?
501Approval received. The application still applies its own permissions and execution policy before carrying out the operation.
Your approval has been sent.
Try the highlighted button or use the controls below.
A clear request and decision can help people reach care information with greater confidence. For staff, NoPass and Desktop Unlock offer separate application and workstation access routes; customer-facing portals can use the relevant PasswordFree® integration.
Ask for a demonstration around the portal or workforce access point you want to improve.
| Journey | Trust question | Operational owner |
|---|---|---|
| Patient portal | Is this the service I use, and did I intend this record-release request? | Portal, identity and patient-support teams. |
| Staff access | Am I returning to the right work application or workstation? | Clinical IT and workforce support. |
Define who may request a record release, how patient consent is recorded, and how access is recovered when a device is lost. An authentication result does not replace the portal’s consent, authorization or clinical policy.
Define a useful decision before planning a wider rollout. Agree scope, responsibilities and success criteria with the team.
Identify the people, application and access or approval moment.
Map enrollment, account ownership, result handling and recovery.
Observe completion, recovery and support workload against agreed criteria.
Use the findings to decide what to change, expand or stop.