LICENSEWARE

Imprivata licensing

This article is an overview of how Imprivata licenses its access management, privileged access, mobile, patient identity and access monitoring products. Deeper articles cover the Master License and Services Agreement, Enterprise Access Management (OneSign and Confirm ID), privileged access (PAM, VPAM and CPAM), and the cloud services priced on devices, patients and monitored users. It is not legal advice.

On This Page

Imprivata licensing is the set of terms under which Imprivata, Inc. sells its identity and access management software, which is used mostly in healthcare. The portfolio covers single sign-on and multifactor authentication (Enterprise Access Management, formerly sold as OneSign and Confirm ID), privileged access management for internal users, vendors and customers, mobile device access (GroundControl), patient identity (Patient Access), and access monitoring (FairWarning and the Access Intelligence Platform).[2][6][8]

One master contract carries the licence grant. The Imprivata Master License and Services Agreement (MLSA) is made between the customer named in the Order Form and Imprivata, Inc. It covers On-Premise Software, Cloud Services, Managed Services, Professional Services and Hardware.[1] Product Specific Terms, “indicated by SKU on the applicable Order Form”, add the pricing metric for each product line.[1] The legal index lists such terms for Access Intelligence, Customer Connect, Enterprise Access, FairWarning, GroundControl, Patient Access, Managed Services, Maintenance and Support, and Hardware.[2] On 2026-08-31 Imprivata archived the earlier End User License Agreement, the SecureLink End User License Agreement and the Master Cloud Services Agreement.[3] Those older texts still explain many installed entitlements, and the deeper articles quote them where they differ.

The grant for On-Premise Software is “limited, non-transferable, non-sublicensable” and limited to the customer’s “direct and internal business purposes”. The Order Form states whether each licence is subscription-based or perpetual.[1] Cloud Services are licensed only for the Subscription Term.[1] Catalog proof: Order Form states whether On-Premise Software is subscription or perpetual; Order Form prevails over the MLSA and Documentation.

Editions

Imprivata publishes no price list. It does publish packaging for Enterprise Access Management and the counting units in its Product Specific Terms.

Product line Unit Imprivata uses Deeper article 
Enterprise Access Management (SSO and MFA; formerly OneSign and Confirm ID) Per user, counted per licensed feature from user policies; Core Access plus add-on modules[6][7] Enterprise Access Management licensing 
Privileged Access Management (PAM) Per named user under the archived EULA[4] Privileged access licensing 
Vendor Privileged Access Management (formerly Enterprise Access) Per Vendor, in SLE tiers of 5 to 100 Vendors[9] same 
Customer Privileged Access Management (formerly Customer Connect) Average Peak Usage of Concurrent Connections[10] same 
GroundControl Per unique Android or iOS Device[13] Mobile, patient and monitoring licensing 
Patient Access Tiers of Patient Enrollments with included Identity Verifications[14] same 
FairWarning and Access Intelligence Platform Data Source Users per Base Subscription[11][12] same 

The Managed Services terms confirm the renaming of the privileged access products: “VPAM formerly known as Enterprise Access and CPAM formerly known as Customer Connect”.[15] This matters for asset managers because the Product Specific Terms page for “Enterprise Access” governs the vendor access service, not Enterprise Access Management.

Metrics

The MLSA defines a User as “an individual authorized by Customer to use the Products pursuant to a subscription”. Users may include employees, consultants, clients, external users, contractors, agents and third parties of the customer and its Affiliates.[1] The Non-Clinical User License is a separate category for people who never treat patients and never use the products to reach the electronic medical record system. Its definition states that a separate licence is needed for each user “regardless of whether the user is actively using the Products”.[1] The archived EULA used the same wording for every user and device licence.[4]

Unit Catalog row Where it applies 
Named user User, Non-Clinical User License All user-licensed products 
Seat per enabled feature Licensed feature seat Enterprise Access Management 
Device Device (OneSign and Confirm ID), Mobile Device Access device, GroundControl Device Medical and mobile devices 
Enterprise Enterprise licence Epic connectors, ProveID Web API 
Vendor Vendor VPAM 
Concurrent connection Concurrent Connections (Average Peak Usage) CPAM 
Monitored user ID Data Source User FairWarning, Access Intelligence 
Patient Patient Enrollment, Identity Verification Patient Access 
Legacy units Managed Identity, Authentication, Named Hospital Identity Governance, PatientSecure 

Counting / floors

Licensed Capacity. The MLSA defines “Licensed Capacity” as the customer’s “authorized usage limits as specified in the applicable Order Form”. The audit clause measures compliance against it, “including the number of Users, and any other applicable metric used in pricing”.[1] Catalog proof: Audit of Licensed Capacity at customer expense.

Named, not concurrent. User licences cannot be shared between shift workers. Each named user needs a licence even when not logged in.[1] In Enterprise Access Management the console counts this per feature: “An enabled user consumes a license for each licensed feature that is enabled in the user policy.”[6] Catalog proof: Each named user needs a licence whether or not active; Enabled users consume a licence per enabled feature.

Affiliates. Products bought by the customer may be used by its Affiliates’ Users. However, “the usage of each Affiliate will be included when measuring usage and subscription compliance”.[1] The Enterprise Access appendix disapplies the Affiliates clause for that product.[9] Catalog proof: Affiliate usage counts toward subscription compliance.

Base Statistics. Most cloud services fix a starting quantity, the Base Statistics, on the initial Order Form. Imprivata then measures usage during the term. Vendors above the base, and Average Peak Usage above the base, are invoiced for the rest of the Subscription Term.[9][10] FairWarning fees rise when Data Source Users grow by 10% or more on a six-monthly Measurement Date.[11] Catalog proof: Vendors above Base Statistics invoiced for rest of term; Average Peak Usage above Base Statistics is invoiced; FairWarning fees rise with Data Source Users above 10%.

Self-certification. A customer that does not use Imprivata’s performance and utilization analytics must send annual self-certification reports. An authorized officer signs them, and they list usage for all Products across all environments, including “peak usage periods and maximum concurrent usage”.[1] Catalog proof: Annual officer-signed self-certification without usage analytics.

Virtualization & partitioning

Imprivata licenses are counted on users, devices, vendors, connections or patients, not on processors. The MLSA does not tie a licence to cores or hosts.[1] Enterprise Access Management runs on Imprivata appliances. The MLSA defines an Appliance as an Imprivata “virtual (or otherwise emulated) appliance that uses virtual processors”.[1] The architecture guide describes appliances delivered as an OVF image for VMware ESX, Microsoft Hyper-V, Nutanix or the customer’s Microsoft Azure tenant. A production enterprise has at least two database appliances, plus service appliances for capacity.[16] Appliances are authorized by serial number from the licence file. The Enterprise Access Management article covers this, and the general concepts are in virtualization and partitioning. Catalog proof: Appliances are authorized from the licence file.

Cloud / BYOL

Cloud Services are licensed for the Subscription Term and only for the customer’s internal business purposes. Under the MLSA the customer is responsible for provisioning Users and “deauthorizing Customer personnel who no longer need access”.[1] Imprivata may store Customer Data in any region where it operates, for example North America or Europe.[1] The privileged access cloud services carry a Service Allocation of network usage and storage. If storage is exceeded, “audit data will automatically be deleted”.[9] No bring-your-own-licence mechanism is published. Catalog proof: Exceeding a Service Allocation throttles or deletes audit data.

Programs

The contract mechanics are covered in Imprivata Master License and Services Agreement.

Out of scope

This page does not cover Imprivata hardware pricing, professional services statements of work, the Business Associate Agreement or the Data Processing Addendum, except where they affect licence counting. Imprivata publishes no list prices, so none are recorded. The OGiTiX End User License Agreement of Imprivata OGiTiX GmbH, which governs software distributed by OGiTiX, is listed on the legal index but not analysed here.[2] No court case about Imprivata software licensing with a primary court record was found, so the wiki has no Imprivata case article.

References

  1. Imprivata Master License and Services AgreementDefinitions; s.2 licence grants, Affiliates, restrictions, Support, audit, Non-Clinical Users; payment; term; evaluation. Undated.Retrieved 2026-10-01.
  2. Imprivata LegalIndex of agreements and Product Specific Terms. Undated.Retrieved 2026-10-01.
  3. Archived Legal AgreementsArchive Date: 8/31/2026.Effective 2026-08-31. Retrieved 2026-10-01.
  4. End User License Agreement for Imprivata Software (archived)Archived as of 2026-08-31. Definitions; s.2 licence grants for OneSign, Confirm ID, Identity Governance, PatientSecure and Privileged Access Manager.Retrieved 2026-10-01.
  5. Imprivata Maintenance and SupportProduct Specific Terms. Undated.Retrieved 2026-10-01.
  6. Imprivata Licensed Features (Enterprise Access Management 26.2 documentation)Topic updated: September 28, 2026.Effective 2026-09-28. Retrieved 2026-10-01.
  7. EAM PackagingCore Access and add-on modules. Undated.Retrieved 2026-10-01.
  8. Privileged Access Security Offering (VPAM documentation)Topic updated: August 21, 2026.Effective 2026-08-21. Retrieved 2026-10-01.
  9. Enterprise Access Cloud Services AppendixVendor metric; SLE tiers. Undated.Retrieved 2026-10-01.
  10. Customer Connect Cloud Service AppendixConcurrent Connections; Average Peak Usage. Undated.Retrieved 2026-10-01.
  11. FairWarning Cloud Service AppendixData Source Users; change-of-scope fee adjustment. Undated.Retrieved 2026-10-01.
  12. Access Intelligence Platform AppendixBase Subscription per Imprivata data source. Undated.Retrieved 2026-10-01.
  13. GroundControl Cloud Service AppendixDevice metric. Undated.Retrieved 2026-10-01.
  14. Imprivata Patient Access Cloud Service AppendixPatient Enrollment tiers; Identity Verifications. Undated.Retrieved 2026-10-01.
  15. Managed Services AppendixNine packages with part numbers. Undated.Retrieved 2026-10-01.
  16. Imprivata Access Management Solutions Overview and ArchitectureTopic updated: May 12, 2026.Effective 2026-05-12. Retrieved 2026-10-01.

See also

Catalog Rows Cited

12Rules15Metrics7Programs

Esc