Care teams and back-office staff needed faster onboarding, less login friction, and better performance during video calls and documentation—without compromising privacy or compliance. Fingerprint scanners proved unreliable in practice due to gloves and disinfectants; the requirement was a hands-free, privacy-conscious solution that always works.
We chose a standardized device package per user group, with IR cameras for Windows Hello Face, Windows 11 Pro, BitLocker encryption, and management via Microsoft Intune and Entra ID.
| Group | Hardware | Features |
|---|---|---|
| Back Office | HP ProBook 4 G1i, 14-inch | Docking + external display |
| Care Teams | Lenovo ThinkBook 16 G8 | Intel® Core™ Ultra 5 (NPU) for on-device AI |
Both profiles use zero-touch setup via Intune Autopilot, Single Sign-On via Entra ID, and policy-based security (Conditional Access, WDAC where relevant).
Hands-free login: works with gloves and masks; no hassle with fingerprints.
Fast and consistent: less login friction, faster access to EHR/EPD and primary tasks.
Secure: local biometrics combined with BitLocker and company policies.
Data location: work files encrypted on the device (BitLocker) and in the tenant; no uncontrolled cloud exfiltration.
Access policy: Entra ID + Conditional Access; fallback for facial recognition via PIN or passkey.
Monitoring: Intune reports on encryption status, policy compliance, and software versions.
Measurable acceleration in deployment, fewer tickets, and higher job satisfaction. Key points:
| KPI | Before | Now |
|---|---|---|
| Device deployment | ±3 hours manual | ±35 min via Autopilot |
| Support tickets (login/deployment) | Baseline | -32% (post-rollout period) |
| Time savings per employee | — | +2 hours per week (indicative) |
Time savings alone yield immediate value. Example calculation (indicative):
| Aspect | Choice |
|---|---|
| Device | HP ProBook 4 G1i – 14-inch + docking + external display |
| Management | Microsoft Intune + Entra ID (SSO), Autopilot |
| Security | BitLocker, Conditional Access, Defender, optional WDAC |
| Practice | Quick start, dual monitors, stable Teams calls, hands-free login |
| Aspect | Choice |
|---|---|
| Device | Lenovo ThinkBook 16 G8 – Intel Core Ultra 5 (with NPU) |
| Management | Microsoft Intune + Entra ID (SSO), Autopilot |
| Security | BitLocker, Conditional Access, Defender |
| Practice | Hands-free login, bright 16:10 screen, local dictation/summarization |
Dictate → summarize → populate fields in EHR (without audio leaving the organization).
Live captions and noise suppression during video calls; less repetition for clients.
Automatically summarize internal memos and protocols into to-dos.
"Logging in without touching and a workstation ready in half an hour—you notice that in every shift."
You get: (1) pilot set with IR cameras and standard profiles, (2) measurement plan for time savings and tickets, (3) advisory report with next steps.
Contact Us