Skip to content
All projects

Allscripts · Case study

Two-Factor Prescription Signing

A web app that lets clinicians sign prescriptions electronically, confirming who they are with two-factor authentication.

Illustration of a prescription tablet with a glowing signature, linked to a security key and a shield with a keyhole.
Illustration1 / 5
Illustration. The other images are screenshots of real public pages.
Role
Software Development Intern: the signing web app and its integration with the Shield platform.
Company
Allscripts

Overview

Built during a 2017 internship with Allscripts’ Shield team, the cloud security platform for authentication and authorization. The app lets clinicians sign prescriptions electronically, with Shield confirming each signature through two-factor authentication. C# and ASP.NET Core on the server, JavaScript in the browser, and SAML for identity.

Problem

A signature on an electronic prescription has to prove the prescriber really signed it. For controlled substances, DEA rules go further and require two-factor authentication at the moment of signing: two of something you know, something you have, and something you are.

Architecture

Two-Factor Prescription Signing system designSigning appShield · security platformClinicianReviews and signsSigning web appASP.NET Core · JSSigning serviceC#Signed recordWho signed, and whenClinical systemPending prescriptionsShieldSign-in · permissionsIdentity providerSAML assertionsSecond factorHeld by the cliniciansignRxPOSTverifySAMLchecksave
RequestData read / writeMoving dots show which way data flows.
  1. Clinician → Signing web app: request, sign
  2. Clinical system → Signing web app: data read / write, Rx
  3. Signing web app → Signing service: request, POST
  4. Signing service ↔ Shield: request, verify
  5. Shield ↔ Identity provider: request, SAML
  6. Shield ↔ Second factor: request, check
  7. Signing service → Signed record: data read / write, save

What made it hard

  • Making the two-factor check part of signing itself, separate from login.
  • Integrating with Shield for authentication and authorization.
  • Carrying identity between systems with SAML.
  • Keeping signing quick for clinicians who do it all day.

Solution

The clinician reviews a pending prescription in an ASP.NET Core web app and chooses to sign. The signing service asks Shield to verify two factors, their credentials and a second factor, with identity carried over SAML. Only when both check out is the prescription marked signed and recorded.

Skills used

  • C#
  • ASP.NET Core
  • JavaScript
  • SAML
  • Two-factor authentication

Impact

  • Let clinicians sign prescriptions electronically, with their identity confirmed at the moment of signing.
  • Built on Shield, so authentication and authorization lived in one shared platform.
  • Learned how healthcare security rules shape software.

Decisions

  1. 01Ask for the second factor at the moment of signing, not only at login.
  2. 02Keep authentication in the shared platform rather than in each app.
  3. 03Use SAML for identity instead of a custom handshake.