This situation is virtually made for client-side certificates: 1) You won't need passwords beyond whatever it takes to log in locally. 2) You can assume the hospital computers are physically secured. (Well, I wouldn't, but apparently they do.) 3) The hospital changes machines very infrequently and probably wants a human in the loop every time a machine changes. 4) You can have certificate generation and registration…
Systems Management vendors love to sell software distribution products to help reduce the distribution requirements for client side certs, but in the end most folks will balk at the price and end up resorting to the sneaker-net approach.