LICENSEWARE

Imprivata mobile, patient and monitoring licensing

This article is about Imprivata products that are not priced per workforce user: GroundControl shared mobile devices, Imprivata Patient Access and the legacy PatientSecure, the FairWarning and Access Intelligence monitoring platforms, and the legacy Identity Governance licence. Enterprise Access Management and privileged access are covered in their own articles.

On This Page

Several Imprivata products are priced on things other than workforce users: shared mobile devices, enrolled patients, identity verification transactions, and the user IDs that a monitoring platform watches. Imprivata mobile, patient and monitoring licensing covers these products. Each has a Product Specific Terms appendix to the Master License and Services Agreement, and each is sold as a Cloud Service for a Subscription Term.[1][2][3][4] Two older products, PatientSecure and Identity Governance, were licensed under the End User License Agreement that Imprivata archived on 2026-08-31. Their units still matter for installed estates.[6]

Editions

Product What is bought Source 
GroundControl A number of unique Devices GroundControl appendix[1] 
Imprivata Patient Access (IPA) A Patient Enrollments tier with included Identity Verifications Patient Access appendix[2] 
FairWarning Cloud Security Platform Base Subscription plus a Data Source Subscription per third-party source (e.g. Salesforce, O365) FairWarning appendix[3] 
FairWarning Drug Diversion Intelligence (DDI), Patient Privacy Intelligence (PPI) Base Subscription (up to three employee data sources included) plus a Data Source Subscription per supported source, such as an EMR FairWarning appendix[3] 
Access Intelligence Platform A Base Subscription per Imprivata data source monitored Access Intelligence appendix[4] 
PatientSecure (legacy) Authentications against an Authentication Baseline; term-based Archived EULA[6] 
Identity Governance (legacy) A User licence per Managed Identity Archived EULA[6] 

The FairWarning Base Subscriptions include “unlimited storage for Customer’s retained active and archived data”. For the Cloud Security Platform, that storage is tied to the Data Source Subscriptions within the Base Statistics.[3] The Access Intelligence Base Subscription includes one Imprivata data source and unlimited storage.[4]

Metrics

  • GroundControl Device. ““Device” means an electronic device that runs on the Android or iOS operating system as specified in the Documentation.” Pricing is “based on Customer’s number of unique Devices”.[1]
  • Patient Enrollment. “A unique patient who, at any time during the Subscription Term, is enrolled to use an Imprivata authenticator in connection with IPA.”[2]
  • Identity Verification. “Each attempted transaction performed within IPA to digitally verify an end user’s identity by validating a government-issued identification document”. IDVs apply only to patient enrollment and account recovery within IPA.[2]
  • Data Source User. “The number of unique individual user IDs across all Data Source Subscriptions monitored by the applicable Cloud Service”.[3] For Access Intelligence it is counted “across the applicable Imprivata data source”.[4]
  • Authentication (PatientSecure). “A biometric scan which may be used to authenticate an individual as measured by Imprivata’s Site Monitor tool”. Partial, unfocused or unsuitable scans are excluded.[6]
  • Managed Identity (Identity Governance). Any employee, contractor, consultant, outsourced worker, administrator or service user “whose user account is in your directory and other applications managed by Imprivata Identity Governance solution”.[6]
  • Named Hospital. A hospital with Licensed Beds, owned or controlled by the customer, named on the Quote or in the PatientSecure Management Tool. The archived EULA counts it together with Clinics.[6]

Counting / floors

GroundControl

A Device that is “lost, stolen, or no longer in use” may be replaced, and access re-allocated to another authorized Device, “provided that in no event may the number of authorized Devices exceed the number of Devices purchased by Customer”.[1] The appendix counts unique Devices, not users, so shift workers sharing one handheld use one licence. Enterprise Access Management’s Mobile Device Access is a separate per-device licence. It counts each device “that has the Imprivata MDA app installed” and also needs per-user Authentication Management and Single Sign-On licences.[8] Catalog proof: GroundControl devices may be replaced but not exceeded; Mobile Device Access is per device and needs AM and SSO.

Patient Access tiers

IPA “is licensed and priced based on a volume-tier model”. If enrollments exceed the licensed tier at any time, the customer “shall be required to purchase the additional Patient Enrollments tier as co-termed with their subscription”. The fee is taken from Imprivata’s then-current price list and pro-rated for the rest of the term.[2]

Patient Enrollments tier Included Identity Verifications per year 
1 – 50,000 9,000 
50,001 – 100,000 18,000 
100,001 – 175,000 31,500 
175,001 – 250,000 45,000 
250,001 – 350,000 63,000 
350,001 – 450,000 81,000 
450,001 – 600,000 108,000 
600,001 – 750,000 135,000 
750,001 – 1,000,000 180,000 

Source: Patient Access appendix.[2] Above 1,000,000 patients, the parties agree the tier and IDV volume between them. The included IDVs are “a finite number” that resets on each renewal or subscription anniversary. Extra IDVs can be bought while IPA is active. Moving to a higher tier mid-year adds a prorated share of that tier’s IDVs.[2] A patient counts once enrolled “at any time during the Subscription Term”. The appendix does not say that unenrolling a patient frees the count. Catalog proof: Exceeding a Patient Enrollment tier requires the next tier; Identity Verification allowance resets annually.

FairWarning and Access Intelligence

The customer states its Data Source Users in the Order Form and represents and warrants that the figure is accurate; it becomes the Base Statistics. For FairWarning, Imprivata reviews the count “Every six (6) months beginning on the effective date of the Subscription Term”. If it has grown by ten percent or more, the Base Statistics reset and the Subject Annual Fees rise “by the same percentage increase”. The customer gets at least two months’ notice and 30 days to validate the findings.[3] The Access Intelligence appendix uses the same method but sets no ten-percent threshold. Any increase over the Base Statistics resets them.[4] In both cases the increase applies for the rest of the Subscription Term and to renewals, unless the parties agree in writing to reset the Base Statistics.[3][4] Merging directories or adding a monitored application with many service accounts can therefore raise the fee. Catalog proof: FairWarning fees rise with Data Source Users above 10%; Access Intelligence needs a Base Subscription per data source.

Legacy PatientSecure and Identity Governance

PatientSecure was licensed for a purchased number of Authentications, the “Authentication Baseline”. Imprivata ran an annual true-up from Site Monitor reports before the end of each annual term. If use exceeded the baseline by ten percent or more, the parties either negotiated fees for the excess or set a revised baseline for the next term. The customer had to keep Site Monitor enabled for auditing at all times.[6] For Identity Governance, the licence fee was “determined by the total number of Managed Identities at the time of your purchase”. When Managed Identities increased, the customer paid additional User licences and Support at the then-current price list.[6] Catalog proof: PatientSecure Authentication Baseline annual true-up; Identity Governance requires a licence per Managed Identity.

Virtualization & partitioning

These products are cloud services or counted in business units such as devices, patients, transactions and monitored IDs, so virtualization does not affect the count. No virtualization rule appears in the appendices.[1][2][3]

Cloud / BYOL

All the current products here are Cloud Services under the MLSA. They are licensed for the Subscription Term, for internal business purposes, and with Support included in the subscription cost.[7] The MLSA makes the customer the party that collects biometric information and requires it to obtain the consents that biometric privacy laws require. This is relevant to IPA and PatientSecure deployments.[7]

Programs

The Managed Services appendix sells packages on top of these subscriptions. For mobile: Mobile Management Services (MS-MGMT-MOBILE-MAM-SUB), Mobile Managed Services (MS-MGMT-MOBILE-SUB) and Essentials Mobile Managed Services (MS-MGMT-MOBILE-MAM1-SUB). For FairWarning: Managed Privacy Services (MS-MGMT-FW-MPS-SUB), Managed Privacy Services LITE (MS-MGMT-FW-MPS-LITE-SUB), Drug Diversion Monitoring Services (MS-MGMT-FW-DDM-SUB) and Advisory Services (MS-ADVIS-FW-SUB).[5] The Mobile Management Services package scales its project hours by deployment size: Small means 2,499 devices or fewer, Medium 2,500 to 19,999 devices, and Large 20,000 devices or more.[5] MPS LITE includes up to four Enforced Policies and is not eligible for more.[5]

For the FairWarning managed services, the appendix says that “Imprivata does not set pricing based on traditional “seat licenses””. It applies a Change-of-Scope Fee Adjustment when a Base Statistic grows by more than ten percent, measured on each half-year anniversary of the contract. Imprivata may check the figures against “any publicly-available information sources” as well as information from the customer.[5] Packages renew for one-year periods unless notice is given at least 30 days before the end of the term.[5] Catalog proof: Managed Services auto-renew yearly with 30 days notice.

Out of scope

This article does not cover Imprivata hardware such as authenticators and badge readers used with Patient Access or mobile devices. It also leaves out mobile device management products from other vendors that GroundControl integrates with, and the Business Associate Agreement. Prices and part numbers for the subscriptions themselves are not published.

References

  1. GroundControl Cloud Service AppendixDevice metric. Undated.Retrieved 2026-10-01.
  2. Imprivata Patient Access Cloud Service AppendixPatient Enrollment tiers and Identity Verifications. Undated.Retrieved 2026-10-01.
  3. FairWarning Cloud Service AppendixBase and Data Source Subscriptions; change-of-scope adjustment. Undated.Retrieved 2026-10-01.
  4. Access Intelligence Platform AppendixBase Subscription per Imprivata data source. Undated.Retrieved 2026-10-01.
  5. Managed Services AppendixMobile and FairWarning packages; change-of-scope fee adjustments. Undated.Retrieved 2026-10-01.
  6. End User License Agreement for Imprivata Software (archived)Archived as of 2026-08-31; s.2(b) Identity Governance, s.2(c) PatientSecure.Retrieved 2026-10-01.
  7. Imprivata Master License and Services AgreementUndated.Retrieved 2026-10-01.
  8. Imprivata Licensed Features (Enterprise Access Management 26.2 documentation)Mobile Device Access. Topic updated: September 28, 2026.Effective 2026-09-28. Retrieved 2026-10-01.

See also

Catalog Rows Cited

7Metrics9Rules2Programs

Esc