Allscripts · Case study
Two-Factor Prescription Signing
A web app that lets clinicians sign prescriptions electronically, confirming who they are with two-factor authentication.

- Role
- Software Development Intern: the signing web app and its integration with the Shield platform.
- Company
- Allscripts
Overview
Built during a 2017 internship with Allscripts’ Shield team, the cloud security platform for authentication and authorization. The app lets clinicians sign prescriptions electronically, with Shield confirming each signature through two-factor authentication. C# and ASP.NET Core on the server, JavaScript in the browser, and SAML for identity.
Problem
A signature on an electronic prescription has to prove the prescriber really signed it. For controlled substances, DEA rules go further and require two-factor authentication at the moment of signing: two of something you know, something you have, and something you are.
Architecture
- Clinician → Signing web app: request, sign
- Clinical system → Signing web app: data read / write, Rx
- Signing web app → Signing service: request, POST
- Signing service ↔ Shield: request, verify
- Shield ↔ Identity provider: request, SAML
- Shield ↔ Second factor: request, check
- Signing service → Signed record: data read / write, save
What made it hard
- Making the two-factor check part of signing itself, separate from login.
- Integrating with Shield for authentication and authorization.
- Carrying identity between systems with SAML.
- Keeping signing quick for clinicians who do it all day.
Solution
The clinician reviews a pending prescription in an ASP.NET Core web app and chooses to sign. The signing service asks Shield to verify two factors, their credentials and a second factor, with identity carried over SAML. Only when both check out is the prescription marked signed and recorded.
Skills used
- C#
- ASP.NET Core
- JavaScript
- SAML
- Two-factor authentication
Impact
- Let clinicians sign prescriptions electronically, with their identity confirmed at the moment of signing.
- Built on Shield, so authentication and authorization lived in one shared platform.
- Learned how healthcare security rules shape software.
Decisions
- 01Ask for the second factor at the moment of signing, not only at login.
- 02Keep authentication in the shared platform rather than in each app.
- 03Use SAML for identity instead of a custom handshake.