Secure access to Optimed NXT with Rublon Multi-Factor Authentication (MFA). Rublon App Shield enables you to add MFA before users access a self-hosted web application without modifying its source code.
When signing in to the application, users can verify their identity using the phishing-resistant FIDO authentication method, which supports FIDO2 security keys and FIDO2 passkeys, such as a Windows Hello passkey, a passkey stored in a password manager, or a passkey on a mobile phone.
What Is Optimed NXT?
Optimed NXT, formerly known as Comarch Optimed NXT, is a Hospital Information System (HIS) designed for hospitals, outpatient clinics, medical practices, and other healthcare facilities. The system supports electronic medical records, patient management, healthcare service settlements, hospital ward and medical practice workflows, and integration with other healthcare systems.
Optimed NXT uses web technology and is accessible through a web browser. When the application is installed locally in the healthcare organization’s infrastructure, access to it can be protected with an additional security layer provided by Rublon App Shield.
Can You Enable MFA and 2FA for Optimed NXT?
You can secure access to a self-hosted Optimed NXT system with Rublon App Shield. The solution acts as a security layer in front of the web application and requires additional identity verification before the user can access the system.
This approach enables you to deploy Rublon MFA independently of the application’s source code. It does not require adding any Rublon MFA software library to the application or installing an agent inside it.
Rublon App Shield is designed for self-hosted web applications, including applications running locally in an organization’s infrastructure. The exact configuration is adapted to how the application is published and to its sign-in and sign-out flows.
Learn more about Rublon App Shield.
How Does Rublon App Shield Protect Access to Optimed NXT with MFA?
Rublon App Shield controls access to the web application before the user establishes the application session.
An example sign-in process works as follows:
- The user opens the protected Optimed NXT address in a web browser.
- Traffic to the application passes through the Rublon App Shield security layer.
- The user is prompted to complete additional authentication with Rublon MFA.
- The user verifies their identity using the selected authentication method.
- After successful verification, the user is granted access to Optimed NXT.
MFA is enforced outside the application itself. This means the organization’s authentication strategy does not have to depend exclusively on the security features provided separately by each specialized application.
MFA Without Changes to the Optimed NXT Source Code
A traditional MFA integration with a web application usually requires source code modifications, an additional plugin, an API integration, or assistance from the application vendor.
Rublon App Shield uses a different approach. A dedicated security layer is placed in front of the protected application, and users must complete multi-factor authentication before they are granted access.
This enables the organization to:
- deploy MFA without modifying the Optimed NXT source code,
- avoid installing an agent inside the protected application,
- retain the existing system sign-in mechanism,
- centrally manage authentication methods and access policies,
- apply the same protection model to other web applications used by the healthcare facility.
Deployment requires configuring Rublon App Shield and directing user traffic to the application through the protected access path. The exact configuration depends on the architecture of the specific Optimed NXT environment.
Signing In to Optimed NXT with Phishing-Resistant FIDO2 Security Keys and FIDO2 Passkeys
Rublon MFA enables organizations to use phishing-resistant authentication methods. Access to Optimed NXT protected by Rublon App Shield can be verified using:
- a hardware FIDO2 security key,
- a Windows Hello passkey,
- a passkey stored in a supported password manager,
- a passkey stored on a mobile phone or another mobile device.
A FIDO2 security key requires physical possession of the device and, depending on its configuration, entering a PIN or completing biometric verification.
FIDO2 passkeys enable authentication using capabilities available on a computer or mobile device. They can use facial recognition, a fingerprint, or the device PIN.
Unlike traditional authentication methods such as TOTP one-time passcodes, FIDO2 mechanisms are bound to the legitimate service. This makes the sign-in process more resistant to phishing and fraudulent websites designed to capture user credentials.
One MFA Solution for the HIS and the Entire Infrastructure
A key benefit of Rublon MFA is the ability to use one solution to protect not only Optimed NXT but also other applications, servers, workstations, remote access services, and network devices used by the healthcare organization.
Protecting access to a Hospital Information System is only one part of securing a healthcare environment. Personnel may also use workstations, Remote Desktop Services, VPNs, servers, administrative panels, and other on-premises and cloud applications.
Instead of deploying a separate two-factor authentication (2FA) solution for every technology, the organization can use Rublon MFA to centrally secure multiple access points.
Depending on the integrations used, Rublon MFA can protect:
- Windows sign-ins,
- RDP connections and Remote Desktop Services,
- VPN access,
- Linux servers,
- applications using RADIUS, LDAP, SAML, and OpenID Connect,
- self-hosted web applications,
- administrative tools and internal systems.
Administrators can manage users, authentication methods, access policies, and event logs as part of a single centralized solution. This helps the organization maintain consistent MFA policies instead of operating separate authentication mechanisms for every system.
Learn more about Rublon MFA for Healthcare.
Why Should You Protect a Hospital Information System with MFA?
A Hospital Information System gives personnel access to information required for patient care and the delivery of medical and administrative processes. If a user account is compromised, an unauthorized person may gain access to patient data, electronic medical records, or administrative functions.
A password alone does not provide sufficient protection if it is phished, guessed, reused in another system, or captured by malicious software.
Multi-factor authentication (MFA) requires an additional identity verification step. Even if an attacker obtains the user’s password, they must still complete the second authentication step.
Deploying Rublon MFA can help a healthcare organization:
- reduce the risk of unauthorized access to the HIS,
- protect the accounts of medical and administrative personnel,
- mitigate the impact of password theft and phishing,
- use phishing-resistant authentication methods,
- standardize protection across the HIS and other infrastructure components,
- record authentication events for monitoring and auditing,
- support organizational and regulatory access control requirements.
Additional Protection for Sensitive Actions
Rublon App Shield can extend protection beyond the initial sign-in screen. After analyzing the interface and workflows of a specific application, the organization can consider implementing additional security rules.
Depending on the technical capabilities of the environment, these rules can:
- require additional authentication before a high-risk action is performed,
- block access to selected pages or application elements,
- prevent unauthorized users from performing specific operations.
Applying such rules to specific areas of Optimed NXT requires prior verification of the application’s behavior and the preparation of appropriate selectors or protection rules.
How to Start the Deployment
To verify whether a specific Optimed NXT environment can be protected with Rublon App Shield, contact Rublon Support.
The following information is useful during the initial assessment:
- how the Optimed NXT system is hosted and published,
- the address users open to access the application,
- the sign-in and sign-out flows,
- how users are identified,
- the directory service used by the organization,
- the required authentication methods,
- high-availability requirements,
- whether a pilot test can be performed.
After the environment has been verified, the appropriate configuration and a detailed deployment guide can be prepared.
Frequently Asked Questions
Does Rublon MFA Require Changes to the Optimed NXT Source Code?
No. Rublon App Shield is designed to protect self-hosted web applications without modifying their source code. You only need to deploy the App Shield layer and direct application traffic through the protected access path.
Can Users Sign In to Optimed NXT with a FIDO2 Security Key?
Yes. Rublon MFA supports hardware FIDO2 security keys. This method is available to users signing in to an application protected by Rublon App Shield.
Does Rublon MFA Support FIDO2 Passkeys for Optimed NXT?
Yes. When Optimed NXT is protected with Rublon App Shield, users can authenticate with FIDO2 passkeys, such as a Windows Hello passkey, a passkey stored in a password manager, or a passkey on a mobile phone.
Does Rublon MFA Protect Only Optimed NXT?
No. The same Rublon MFA solution can also protect other web applications, Windows sign-ins, RDP connections, VPNs, servers, and other parts of the IT infrastructure.
Related Posts
Secure Hospital Information Systems (HIS) with Rublon MFA
Multi-Factor Authentication (MFA) for Healthcare
Agentless MFA for Self-Hosted Web Applications Without Code Changes With Rublon App Shield
Secure Electronic Health Records (EHR) with Rublon MFA