HIPAA Two Factor Authentication
The HIPAA Security Rule requires covered entities and business associates to verify that anyone accessing electronic protected health information (ePHI) is who they claim to be. It does not yet name multi factor authentication, but risk analyses keep arriving at it, and HHS has proposed making it a requirement. This page explains where the HIPAA MFA requirement stands and how Spriv protects ePHI access without ever receiving PHI.
Does HIPAA require MFA?
Not by name, under the Security Rule as it currently stands. But three of its standards point squarely at strong authentication for ePHI access security, and HHS guidance treats MFA as a key safeguard.
164.312(d) Person or entity authentication
Requires procedures to verify that a person or entity seeking access to ePHI is the one claimed. A password alone is the weakest way to meet it.
164.312(a) Access control
Requires technical policies and procedures that allow access to ePHI only to the people and programs that have been granted access rights.
164.308(a)(1) Risk analysis
Requires an accurate assessment of risks to ePHI and measures to reduce them. Stolen credentials are a leading risk, and MFA is a common response.
Where healthcare organizations need two factor authentication
The places a risk analysis usually flags are the ones where a stolen password goes furthest.
Remote access to EHR systems
Clinicians and billing staff working from home, and vendors supporting systems remotely, reach patient records from outside the building. A second factor on the phone means a phished password cannot open the record from somewhere else.
RDP into clinical and application servers
Remote Desktop to the servers behind EHR, imaging and practice-management software is a common ransomware entry point. Spriv adds MFA to the Windows login screen for local and RDP sessions. Adaptive MFA for RDP.
Shared workstations on the ward
Nursing stations and exam-room computers are used by many people in a shift. Spriv ties each login to the individual's paired phone, and its continuous authentication detects when the user has left the authorized computer. Continuous MFA overview.
Administrator and IT accounts
Accounts that manage servers, backups and directories can reach every record at once. Keep them on Allow/Deny for production access, and Adaptive MFA for routine logins.
Strong authentication without slowing down care
Clinicians cannot wait on a code between patients. Spriv verifies the second factor in the background on a trusted workstation and interrupts only when something looks wrong.
Pair the phone once
An administrator adds the user, Spriv sends a pairing link, and the user opens it in the Spriv app on their phone.
Approve the first login
The first sign-in from a workstation is approved on the phone. Spriv records that computer with the environment the phone reports.
Routine logins clear silently
When the workstation and phone match, access is granted in as little as 175 milliseconds. A new computer or location gets challenged. Windows login MFA.
No PHI goes to Spriv
Spriv checks identity, not records. It confirms that the phone and the computer are in matching locations and never shares the phone's actual location. Zero personally identifiable information is transferred.
Whether you need a business associate agreement with any vendor is a determination for your privacy officer or counsel.
-
Lost phone
An administrator swaps the phone in the management portal in under a minute. Account recovery
-
Forgotten phone
An administrator can postpone the second factor for up to 72 hours. Document and approve it as an exception.
-
Staff leaving
Set the user to Deny or Locked in the control panel so their phone stops working as a factor.
HIPAA two factor authentication questions
If HIPAA does not name MFA, why deploy it now?
Because the authentication and risk analysis standards already apply, and stolen credentials are a common way into healthcare systems. MFA is a direct, documentable answer, and it gets you ahead of the proposed update if it is finalized.
Is Spriv HIPAA certified?
There is no official HIPAA certification for products. Spriv's MFA is built to satisfy HIPAA's authentication expectations and helps you meet them; your compliance program decides the rest.
What if a clinician's phone has no signal?
TOTP codes are generated on the phone every 30 seconds and work with no internet or carrier signal, which suits basements, imaging suites and other dead zones.
Does Spriv log users out of shared computers?
Spriv's continuous authentication detects when the user has left the authorized computer and tells your platform, which can then end the session. It can support your automatic logoff procedures; it does not replace them.
Related pages
Protect ePHI access in the background
Two free users and two free servers, no credit card. Install on a clinical server in under five minutes.