Over the years, healthcare IT arrived at an assumption that virtualization creates friction; clinicians resent it, and adding security makes the experience worse. It shows up in RFPs, in steering committee conversations, in the way organizations have walked away from hosted EUC deployments and concluded that centralized EUC is no longer the right solution for clinical environments. The implication is that speed, cost, and security cannot coexist. Making EHR access more secure means making it harder to use, and the compute model itself is viewed as a major contributor to healthcare inefficiency and poor patient experiences.

At Citrix, we believe that is not necessarily the case and that it comes from a specific root cause.

The friction clinicians’ experience when accessing EHR platforms is almost never caused by the centralized EUC strategy. It’s often the layers of security solutions added on top of each other over time. It’s operating system-level policies, registry edits, and login scripts which have evolved in number and complexity over time with limited change management and guardrails. At this point it works; clinicians can access their applications and do their job but are forced to wait at logon screens for far too long while a healthcare professional is bedside. The problem is that no one really understands that line of code with a comment above it reading, “Do not touch – the EMR will not run without this command,” written by someone who retired 10 years ago on Windows Server 2003. It’s layer upon layer with no thought to the bigger picture that leads to a logon performance problem that takes 30 seconds of precious time to process on every user logon. The solution for the longest time has been to throw more resources at it, faster CPUs, more RAM, SSDs, etc. It’s this mentality that has gotten us to today’s sentiment.

Fast forward to today where many of our competitors say that the solution to this is to build brand new, decentralized physical devices with a new identity platform, new endpoint management platform, new security software. Of course, it will be faster … it’s all being built fresh and brand new! But along with being brand new, the entire EUC design has changed. When Wi-Fi association and authentication is a separate step, it slows clinicians down. When session management is an afterthought, roaming between rooms means logging in from scratch. When data protection depends on what happens at the endpoint, every device becomes a risk that needs critical patches, management, and encryption. The bottom line, decentralized EUC, while it may be faster in the short-term, will it truly move the needle?

With modernized, centralized EUC, security stops being the thing that slows clinicians down and starts being the thing that makes fast, secure, access possible. The badge tap that gets a nurse into the EMR in under five seconds is not speed despite security. It is speed because security is built in.

In this article, I address the myth that hosted delivery is the source of clinical friction, walk through what a properly designed architecture delivers at every moment of a clinical shift, and make the case that the tradeoff between secure and fast is one healthcare organizations should not have to accept.

Bolted on security creates friction

According to KLAS Research’s 2025 Clinician EHR Experience Report, slow EHR response times, including login delays, application launch latency, and authentication interruptions, are among the top drivers of poor clinician experience. Healthcare IT News has documented the same pattern, noting that physicians cite “interminable sign-ins” as a daily frustration that compounds into burnout.

Picture a charge nurse mid-shift. She steps away from a patient room, moves to the next workstation, and must authenticate at the OS, authenticate into the EMR, and sometimes authenticate again for a specific clinical function before she can pull up the chart she needs. Each layer was added at a different time, by a different team, to address a different compliance requirement. None of them were designed with her workflow in mind. The result is a stack of gates she passes through every time she sits down, every time she steps away, every time she moves rooms.

In a healthcare environment where a nurse may touch a dozen workstations during a single shift, that friction is not a minor inconvenience. It is a structural drain on the time available for patient care.

Built-in security means friction-free access

All is not lost! You don’t have to rebuild a brand-new environment to get these benefits. In a properly configured Citrix DaaS Cloud or Local application virtualization environment, the security controls and access experience are the same thing, not two things layered on top of each other.

Consider what happens at each moment that matters in a clinical shift:

  1. The moment a clinician badges into the building for the first time that day.
    With session prelaunch and remote start, Citrix DaaS Cloud initializes the user’s workspace in the background, triggered by a badge swipe at the ward entrance. By the time the clinician sits down, the session is ready. Citrix Workspace Environment Management (WEM) has already applied policies and mapped resources, without blocking the desktop from appearing. The authentication happened when the badge was tapped. It was not a separate step. It was the step. In testing with real healthcare environments, these optimizations combined to improve logon times by an average of 35% over traditional approaches. Integrating these two systems is not a costly activity either.
  2. The moment a clinician moves to a different room.
    Session roaming means the Citrix DaaS Cloud session follows the clinician to the next workstation. Combined with Imprivata Tap and Go badge authentication integrated natively into the workspace, the workflow is: badge in, session resumes in under five seconds, continue charting where they left off. Badge out, session locks and secures. The security event and the workflow event are the same event. There is no security tax on mobility because the mobility is built on top of the security, not around it. Research suggests that this kind of optimized digital workspace can return up to 45 minutes per clinician per shift.
  3. The moment a clinician closes a session.
    In a traditional PC environment, patient data remains on the endpoint: cached files, browser history, clipboard contents. In a Citrix environment, there is nothing to clean up because the data never leaves the data center. What traveled across the network was an encrypted display stream. Pixels, not patient records. Clipboard policies, Citrix DaaS App Protection, and Citrix Session Insights are all enforced at the session layer, not at the endpoint.

What this looks like in practice

One large integrated health network operating across more than a dozen campuses was caught in exactly the tension described above. More than 20,000 users needed fast, reliable EMR access across thousands of shared devices. Their previous roaming fat client desktop solution was slow to load and slow to launch the EMR. Clinical staff found workarounds. IT managed complaints.

The problem was not that they had too much security. It was that the security and the access experiences were designed independently of each other.

After moving to Citrix DaaS Cloud or Local, clinicians gained access to electronic health records 88% faster, consistently hitting under five seconds from badge tap to open chart. A care team member can now walk up to any of more than 9,500 devices across the organization, tap a badge, and be in Epic with their session ready. The IT team managing this environment—a team of three—supports more than 20,000 users every day.

Clinical staff describe Citrix as part of their standard daily process. That is the signal the architecture is working: when the technology disappears into the workflow.

The case for centralized delivery

Some organizations are considering a move away from desktop virtualization toward locally installed EHR applications, with the argument that it improves logon performance and app responsiveness thereby reducing clinician friction. That framing is a misunderstanding of how the logon process works and what contributes to its performance. Technology-wise, it’s fair to say that virtualization can increase logon time. It is a second Windows session that a user must “log on to” which also requires loading a profile, starting processes, etc. The challenge is that in many cases, policy and script configurations have proliferated and grown over the years, creating extra bloat. The solve is often a broader system architecture problem. Organizations that address the architecture, as the health network described earlier, achieve badge-to-chart access in under five seconds across thousands of devices. Clinician experience is resolved well before it becomes a reason to change delivery models.

However, with organizations that do pursue a locally installed EHR approach, what these organizations leave behind is resilience. That’s a significant problem with potential future regulatory ramifications. When the CrowdStrike incident in July 2024 took down approximately 8.5 million Windows endpoints worldwide, organizations running virtualized desktop environments rolled back a single golden master image and restored access in hours. Organizations dependent on locally managed PCs faced an estimated 2,500 staff hours of recovery over 15 to 25 days. The proposed HIPAA Security Rule update sets a 72-hour recovery requirement for EHR access following a cyber incident. Centralized delivery is built for that standard. Distributed endpoint management is not.

Local installation also carries ongoing operational costs that compound quietly. Every endpoint becomes a managed application host with its own patching cycle, driver validation requirements, and OS compatibility testing against every third-party clinical application in the environment. In a centralized model, that work happens once, against one image. The difference grows with every device added to the fleet.

Health-ISAC tracked 575 breaches of health sector organizations in 2025, up from 179 in 2021. The architecture that keeps PHI off the endpoint, enforces consistent policy regardless of device or location, and recovers in hours is not a legacy choice. It is the operationally sound one.

The right architecture makes the tradeoff disappear

When the security and clinician experience are designed together, clinicians get both. If they are designed separately, you are constantly negotiating between them.

When you centralize EMR delivery with Citrix, that negotiation ends. Friction drops because the authentication is the workflow. Recovery accelerates because the data was never at the edge. Security becomes consistent because policy is enforced at the session layer, not at thousands of individual endpoints. Clinicians get their time back. IT gets control. And the organization builds the resilience that regulators, boards, and patients increasingly demand.

As Gartner noted in its 2025 Critical Capabilities for Desktop as a Service report, Citrix is best suited for organizations in regulated industries and those leveraging business continuity use cases with large-scale, complex needs spanning on-premises, public, and private clouds.

When a clinician taps a badge, sees their EMR session open in under five seconds, moves to the next room and picks up where they left off, and never once thinks about where the data is or who can see it, that is not a tradeoff. It is proof that the working assumption was wrong.

Take the next step

While this all sounds great and all of this exists today, we’re not stopping here. We are continuously looking at ways to innovate and make the experience better for our end users in healthcare and IT professionals who support them. We are continuously looking at ways to make the experience better; more cost-efficient while maintaining the strong security posture required to protect patient data.

If your environment is not hitting these benchmarks, it is almost always a configuration problem, not a platform problem. Citrix WEM is one of the highest-impact levers available to healthcare IT teams, and we will help you use it at no cost. Download our EHR Logon Optimization Configuration Guide and reach out to your Citrix account team to get started.