Table of Contents
PBM authentication challenges
Don't have the time to read the entire post? Our human writers will be sad, but we understand. Summarize the post with your preferred LLM here instead.
Pharmacy benefit managers, or PBMs, play a key role in how most Americans receive their prescriptions. The three biggest companies—Express Scripts, CVS Caremark, and Optum Rx—now handle about 80% of all prescription claims in the country. As PBMs add more member apps, specialty pharmacy programs, and connect with providers and electronic health records, identity and authentication systems have become essential for both medication access and compliance. PBM leaders are working to make these digital services easy to use while protecting member and pharmacy data.
At the same time, PBMs manage a much more complex network of stakeholders than most other healthcare platforms.
There are several different user groups, such as members, pharmacies, prescribers, employers, and brokers or third-party administrators. Each group needs its own portal and specific access permissions.
PBMs are a prime target for credential stuffing and account takeovers because member accounts contain personal health information, payment data, and access to specialty drugs.
Many PBMs still use older or custom-built authentication systems that were developed separately for each portal over the years.
PBMs face a heavy regulatory burden, including HIPAA, state PBM licensing laws, and new transparency rules from the FTC.
Frequent mergers and acquisitions mean PBMs must quickly integrate identity systems across newly combined platforms.
These challenges make it hard for traditional, one-size-fits-all authentication systems to keep up with the way PBMs work. PBMs need flexible identity systems that can support different users without increasing risk or slowing down teams.
Here are some of the most common authentication challenges that PBMs deal with:
PBM authentication challenges
Members
Identity systems are meant to keep member and pharmacy data safe, but for PBMs, these systems can sometimes make it harder for people to get their prescriptions. Most authentication models are built for consumer apps, where users have their own devices, steady internet, and are comfortable with technology. Many PBM members, though, face a different reality.
Many PBMs face challenges such as:
Account takeover risk: Member portals hold PHI, payment details, and specialty drug access, making them a high-value target for credential stuffing and fraud.
Password fatigue: Members often forget their passwords or have trouble with frequent resets, which can cause them to abandon logins when they need to refill a prescription.
Shared or family accounts: Several people in a household might use the same login to manage benefits, which can lead to confusion about access and privacy.
Fragmented experiences: When members switch between mail-order, specialty, and retail pharmacy services, they often deal with different login experiences on each system.
As a result, some members give up on digital tools altogether, falling back on slower, costlier phone-based processes or, worse, becoming victims of account takeover before anyone notices. For PBMs working to reduce cost and friction across the system, authentication needs to be secure but also built for how members actually use these services.
Also Read: Healthcare Identity and Access Management Best Practices
IT and engineering teams
Authentication challenges impact not only members but also the teams who keep PBM systems running. PBMs often have small engineering teams that support many portals for members, pharmacies, providers, employers, and brokers. When authentication is fragmented, these teams spend too much time maintaining login systems instead of building new features.
The complexity grows as PBMs expand integrations. Many connect to EHRs and prescriber workflows through electronic prior authorization and FHIR-based standards, like the Da Vinci Project's Prior Authorization Implementation Guide, linking prescriber systems directly to formulary and coverage data. These integrations streamline care, but they also introduce identity and authorization challenges that stretch already limited engineering resources.
Key challenges IT and engineering teams must manage include:
Portal sprawl: Member, pharmacy, employer, and broker portals are often built as separate systems over time, each with its own authentication logic.
Regulatory pressure: Recent FTC settlements with Express Scripts and Caremark are pushing PBMs toward greater transparency, adding new compliance and audit requirements that directly affect identity systems.
Complex integrations: Teams must support OAuth flows, token exchanges, and API-level authorization across ePA, SMART on FHIR, and EHR-connected workflows.
Consolidation: Rapid M&A activity across the PBM market forces teams to merge or federate identity systems quickly, often under tight timelines.
Tenant-level requirements: Different tenants, whether an individual employer, a broker network, or a pharmacy chain, often need their own authentication methods, role structures, and branding, which a single generic login flow can't easily support.
Onboarding friction: Getting a new enterprise tenant up and running with working SSO and provisioning can take weeks of back-and-forth between engineering and the customer's IT team, delaying time to value.
Identity management support tickets: Routine requests, like adding a user, resetting access, or updating a role, often land on engineering instead of the tenant's own admin, adding to an already stretched support queue.
The result is mounting operational overhead for engineering teams that are already stretched thin. PBMs need to simplify identity management so teams can spend less time on authentication and more time improving the member and partner experience.
Identity best practices for PBMs
PBMs need to keep member and pharmacy data safe while also making it simple for members to manage prescriptions, refills, and benefits online. As PBMs add specialty pharmacy programs, provider integrations, and more digital touchpoints, authentication must work hand in hand with security and easy access.
Effective identity approaches focus on:
Reducing reliance on passwords for members, using one-time codes, magic links, and passkeys, so fewer people abandon a login while checking benefits or refilling a prescription.
Using risk-based and adaptive MFA, extra verification is only required for sensitive actions, like specialty drug requests or account changes, rather than every single login.
Unifying identity across every portal type, including member, pharmacy, employer, and broker, instead of maintaining separate authentication systems that were built at different times.
Applying fine-grained authorization, so members, brokers, and plan administrators each get precisely the access their role requires, and nothing more.
Keeping detailed, audit-ready authentication logs, given rising HIPAA, state PBM licensure, and FTC transparency requirements.
To put these ideas into action, PBMs should consolidate authentication across portals wherever possible, apply consistent access policies across every user type, and review authentication logs regularly to stay ahead of both fraud and regulators.
When PBMs balance strong security with easy-to-use design, they can cut fraud, keep pace with growing regulatory demands, and free up engineering teams to focus on the product instead of patching together login systems.
How Descope helps PBMs adopt modern customer identity
PBMs often need to update their authentication systems, but many teams are already stretched thin. Adding stronger security, making things easier for members, and connecting different portals can be tough with limited resources. Modern identity platforms can help PBMs add secure authentication and make operations simpler.

Descope lets PBMs set up modern authentication that makes it easier for members to log in, while still keeping security and compliance strong. With Descope, PBMs get access to:
Passwordless authentication: Supporting one-time codes, magic links, and passkeys to reduce password friction and cut abandonment for members managing prescriptions and benefits.
Adaptive MFA: Adding additional verification only when risk is detected, protecting sensitive actions like specialty drug requests without introducing unnecessary login steps.
Multi-tenancy: Treating each employer, broker, and pharmacy partner as its own tenant, with independent SSO connections, MFA policies, and role structures, all managed from one identity layer instead of duplicated systems.
Identity federation and SSO: Unifying member, pharmacy, employer, and broker portals under a single identity layer, reducing maintenance overhead across previously siloed systems.
Self-service SSO Setup Suite: Letting employer and broker tenants configure their own SSO and SCIM connections through a guided portal, cutting onboarding time from weeks to minutes instead of looping in engineering for every setup.
Fine-grained authorization: Giving members, brokers, and plan administrators precisely scoped access based on their role, without extra engineering lift.
Delegated admin: Handing routine identity tasks, like adding users or updating roles, to each tenant's own admins through a self-service portal, cutting down the identity-related support tickets that would otherwise land on engineering.
Family and shared account support: Letting members manage benefits for dependents or household members under precisely scoped roles, instead of resorting to risky password sharing on a single login.
Visual authentication workflows: Allowing lean teams to build and modify member, pharmacy, and partner login journeys without heavy custom development.
SMART on FHIR support: Handling user authentication, consent, and token issuance so PBM systems can securely connect to EHR platforms.
Fraud and account takeover prevention: Protecting high-value member and pharmacy accounts from credential stuffing and takeover attempts.
Flexible integrations: Connecting CDPs, SMS/OTP providers, and audit and logging tools with plug & play connectors to support compliance and analytics needs.
These capabilities help PBMs deliver secure, low-friction authentication experiences for members and partners while easing the operational burden on internal engineering teams.
Success story: How SmithRx unified identity across three portals
SmithRx is a full-service PBM built around transparency and low-cost access to prescription drugs, serving employers, brokers, and members through three separate portals. As SmithRx broke a monolithic application into microservices, its engineering team realized authentication needed to move in the opposite direction: consolidation, so they went looking for identity federation across all three portals, multiple authentication methods, and a path toward fine-grained authorization, without draining their lean team. An earlier CIAM vendor fell short, treating FGA as a costly add-on rather than a core capability.
With Descope, SmithRx had tenant SSO and self-service SSO configuration testing running in the first week of implementation, and every user imported within two weeks, despite a holiday-season code freeze. Descope Flows also solved a specific edge case: checking whether a user's organization had SSO enabled without relying on email domain matching, since many members sign up with personal email addresses. The result is one identity layer serving members, employers, and brokers, with fine-grained authorization now underway to give each persona even more precisely scoped access.
Modern identity keeps PBMs secure, compliant, and fast
As prescription benefits move further online and regulatory scrutiny intensifies, authentication has to reflect the reality PBMs operate in: multiple stakeholder types, high-value targets for fraud, and mounting compliance requirements. Traditional, siloed login systems often add risk and slow teams down instead of protecting them.
Modern authentication helps PBMs reduce fraud and friction while keeping pace with regulation. Flexible, unified identity reduces member abandonment, strengthens protection against account takeover, and eases the burden on lean engineering teams.
Descope's drag & drop CIAM platform supports passwordless auth, adaptive MFA, and federated access across every portal type. Teams like SmithRx, GoodRx, Collabrios Health, and Owens & Minor use Descope to improve onboarding and security and reduce engineering effort.
If you're evaluating healthcare-focused customer IAM platforms, check out our docs. If you'd like a demo, meet with our auth experts. Also, if you want to try Descope yourself, sign up for a Free Forever Account and start dragging & dropping your auth today!



