Secure browser-based access to AMMS (Asseco Medical Management Solutions) with multi-factor authentication provided by Rublon MFA. The Rublon App Shield solution enables you to add MFA before users access a self-hosted web application without modifying its source code.
When signing in to the application, users can verify their identity using phishing-resistant authentication methods, including FIDO2 security keys and FIDO2 passkeys, such as a Windows Hello passkey, a passkey stored in a password manager, or a passkey on a mobile phone.
What Is AMMS?
AMMS, or Asseco Medical Management Solutions, is a comprehensive, integrated suite of IT systems designed for large and medium-sized hospitals, clinics, medical centers, outpatient clinics, and ambulatory care facilities.
The solution covers, among other areas, the medical HIS area and the administrative and management ERP area. It supports electronic health records, patient flow management, outpatient clinic and hospital ward workflows, settlements with the Polish National Health Fund (NFZ), medication management, diagnostics, finance, human resources, materials management, and management reporting.
The AMMS system provides a browser-based interface and supports mobile devices. If a browser-based AMMS component is hosted in the healthcare organizationโs infrastructure or in a data center controlled by the organization, access to it can be protected with an additional phishing-resistant security layer provided by Rublon App Shield.
Can You Enable MFA and 2FA for AMMS?
You can secure access to a self-hosted AMMS web interface with Rublon App Shield. The solution acts as a security layer in front of the web application and requires additional identity verification before the user can access the system.
This approach enables you to deploy Rublon MFA independently of the source code of the protected AMMS component. It does not require adding any Rublon MFA software library to the application or installing an agent inside it.
Rublon App Shield is designed for self-hosted web applications, including applications running locally in an organizationโs infrastructure. The exact configuration is adapted to how the application is published and to its sign-in and sign-out flows.
Learn more about Rublon App Shield.
How Does Rublon App Shield Protect Access to AMMS with MFA?
Rublon App Shield controls access to the web interface before the user establishes the application session.
An example sign-in process is as follows:
- The user opens the protected AMMS address in a web browser.
- Traffic to the application passes through the Rublon App Shield security layer.
- The user is prompted to complete additional authentication with Rublon MFA.
- The user verifies their identity using the selected authentication method.
- After successful verification, the user is granted access to the AMMS interface.
MFA is enforced outside the application itself. As a result, the organizationโs authentication strategy does not have to rely solely on the security features available separately in each specialized system.
The exact sign-in flow and the range of AMMS components that can be protected must be verified for the specific deployment.
MFA Without Changes to the AMMS Source Code
A traditional MFA integration with a web application usually requires source code modifications, an additional plugin, an API integration, or assistance from the application vendor.
Rublon App Shield uses a different approach. A dedicated security layer is placed in front of the protected application, and users must complete multi-factor authentication before they are granted access.
This enables you to:
- deploy MFA without modifying the source code of the browser-based AMMS component,
- avoid installing an agent inside the protected application,
- retain the existing system sign-in mechanism,
- centrally manage authentication methods and access policies,
- apply the same protection model to other web applications used by the healthcare organization.
Deployment requires configuring Rublon App Shield and directing user traffic to the application through the protected access path. The details depend on the architecture of the specific AMMS environment and how its web components are made available.
Signing In to AMMS with Phishing-Resistant FIDO2 Security Keys and FIDO2 Passkeys
Rublon MFA enables organizations to use phishing-resistant authentication methods. Access to the AMMS interface protected by Rublon App Shield can be verified using:
- a hardware FIDO2 security key,
- a Windows Hello passkey,
- a passkey stored in a supported password manager,
- a passkey stored on a mobile phone or another mobile device.
A FIDO2 security key requires physical possession of the device and, depending on its configuration, entering a PIN or completing biometric verification.
FIDO2 passkeys enable authentication using capabilities available on a computer or mobile device. They can use facial recognition, a fingerprint, or the device PIN.
Unlike traditional authentication methods such as TOTP one-time passcodes, FIDO2 mechanisms are bound to the legitimate service. This makes the sign-in process more resistant to phishing and fraudulent websites designed to capture user credentials.
One MFA Solution for the HIS and the Entire Infrastructure
A key benefit of Rublon MFA is the ability to use one solution to protect not only browser-based access to AMMS but also other applications, servers, workstations, remote access services, and network devices used by the healthcare organization.
Protecting access to a Hospital Information System is only one part of securing a healthcare environment. Personnel may also use workstations, Remote Desktop Services, VPNs, servers, administrative panels, and other on-premises and cloud applications.
Instead of deploying a separate two-factor authentication (2FA) solution for every technology, the organization can use Rublon MFA to centrally secure multiple access points.
Depending on the integrations used, Rublon MFA can protect:
- Windows sign-ins,
- RDP connections and Remote Desktop Services,
- VPN access,
- Linux servers,
- applications using the RADIUS, LDAP, SAML and OpenID Connect protocols,
- self-hosted web applications,
- administrative tools and internal systems.
Administrators can manage users, authentication methods, access policies and event logs as part of a single centralized solution. This helps maintain consistent MFA policies across the organization instead of operating separate mechanisms for each system.
Learn more about Rublon MFA for Healthcare.
Why Protect a Hospital Information System with MFA?
A Hospital Information System gives personnel access to information required for patient care and the delivery of medical and administrative processes. If a user account is compromised, an unauthorized person may gain access to patient data, electronic health records, or administrative functions.
A password alone does not provide sufficient protection if it is phished, guessed, reused in another system, or captured by malicious software.
Multi-factor authentication (MFA) requires an additional identity verification step. Even if an attacker obtains the userโs password, they must still complete the second authentication step.
Deploying Rublon MFA can help a healthcare organization:
- reduce the risk of unauthorized access to the HIS,
- protect the accounts of medical and administrative personnel,
- mitigate the impact of password theft and phishing,
- use phishing-resistant authentication methods,
- standardize protection across the HIS and other infrastructure components,
- record authentication events for monitoring and auditing,
- support organizational and regulatory access control requirements.
Additional Protection for Sensitive Actions
Rublon App Shield can also extend protection beyond the sign-in screen. After analyzing the interface and workflows of a specific application, the organization can consider implementing additional security rules.
Depending on the technical capabilities of the environment, these rules can:
- require additional authentication before a high-risk action is performed,
- block access to selected pages or application elements,
- prevent unauthorized users from performing specific operations.
Applying such rules to specific areas of AMMS requires prior verification of the application interface and the preparation of appropriate selectors or protection rules.
How to Start the Deployment
To verify whether a specific AMMS environment can be protected with Rublon App Shield, contact Rublon Support.
The following information is useful during the initial assessment:
- the AMMS version and modules in use,
- how the AMMS web interface is hosted and published,
- the address users open to access the application,
- the sign-in and sign-out flows,
- how users are identified,
- the directory service used by the organization,
- the required authentication methods,
- high-availability requirements,
- whether a pilot test can be performed.
You must also determine which AMMS components are available through a web browser and which use another type of client. Rublon App Shield protects web applications whose traffic is directed through its security layer.
After the environment has been verified, the appropriate configuration and a detailed deployment guide can be prepared.
Frequently Asked Questions
Does Rublon MFA Require Changes to the AMMS Source Code?
No, not when the web interface is protected by Rublon App Shield. The solution is designed to protect self-hosted web applications without modifying their source code. You only need to deploy the App Shield layer and direct application traffic through the protected access path.
Can Users Sign In to AMMS with a FIDO2 Security Key?
Yes. Rublon MFA supports hardware FIDO2 security keys. This method is available to users accessing a web interface protected by Rublon App Shield.
Does Rublon MFA Support FIDO2 Passkeys for AMMS?
Yes. When using Rublon App Shield, users can authenticate with FIDO2 passkeys, such as a Windows Hello passkey, a passkey stored in a password manager, or a passkey on a mobile phone.
Can Rublon App Shield Protect All AMMS Modules?
Rublon App Shield can protect self-hosted AMMS web components whose user traffic can be directed through the App Shield layer. The scope of protection depends on the architecture of the specific deployment and how individual modules are made available.
AMMS components that do not operate as web applications are not automatically protected by Rublon App Shield. In this case, you should determine whether access can be secured using another Rublon MFA integration, such as protection for Windows sign-ins, RDP connections, or VPN access.
Does Rublon MFA Protect Only AMMS?
No. The same Rublon MFA solution can also protect other web applications, Windows sign-ins, RDP connections, VPNs, servers, and other parts of the IT infrastructure.
Related Posts
Secure Hospital Information Systems (HIS) with Rublon MFA
Secure ERP Systems with Rublon MFA
Multi-Factor Authentication (MFA) for Healthcare
Agentless MFA for Self-Hosted Web Applications Without Code Changes With Rublon App Shield