Compliance · Healthcare

HIPAA Two Factor Authentication

The HIPAA Security Rule requires covered entities and business associates to verify that anyone accessing electronic protected health information (ePHI) is who they claim to be. It does not yet name multi factor authentication, but risk analyses keep arriving at it, and HHS has proposed making it a requirement. This page explains where the HIPAA MFA requirement stands and how Spriv protects ePHI access without ever receiving PHI.

One-time access password sent by text message as a fallback second factor for HIPAA two factor authentication
HIPAA 2FA · Identity checked, no PHI shared
0
Personally identifiable information transferred
0
Separate channels for each out-of-band check
0 ms
Typical second-factor time on a trusted workstation
0 s
Or less to swap a lost phone in the portal
The rule today

Does HIPAA require MFA?

Not by name, under the Security Rule as it currently stands. But three of its standards point squarely at strong authentication for ePHI access security, and HHS guidance treats MFA as a key safeguard.

164.312(d) Person or entity authentication

Requires procedures to verify that a person or entity seeking access to ePHI is the one claimed. A password alone is the weakest way to meet it.

164.312(a) Access control

Requires technical policies and procedures that allow access to ePHI only to the people and programs that have been granted access rights.

164.308(a)(1) Risk analysis

Requires an accurate assessment of risks to ePHI and measures to reduce them. Stolen credentials are a leading risk, and MFA is a common response.

Proposed, not final. In January 2025, HHS published a proposed update to the Security Rule (a notice of proposed rulemaking) that would require MFA for access to ePHI, with limited exceptions. Check its current status, and how your risk analysis applies, with your compliance officer or counsel. This page is general information, not legal advice.
Where ePHI is exposed

Where healthcare organizations need two factor authentication

The places a risk analysis usually flags are the ones where a stolen password goes furthest.

Remote access to EHR systems

Clinicians and billing staff working from home, and vendors supporting systems remotely, reach patient records from outside the building. A second factor on the phone means a phished password cannot open the record from somewhere else.

RDP into clinical and application servers

Remote Desktop to the servers behind EHR, imaging and practice-management software is a common ransomware entry point. Spriv adds MFA to the Windows login screen for local and RDP sessions. Adaptive MFA for RDP.

Shared workstations on the ward

Nursing stations and exam-room computers are used by many people in a shift. Spriv ties each login to the individual's paired phone, and its continuous authentication detects when the user has left the authorized computer. Continuous MFA overview.

Administrator and IT accounts

Accounts that manage servers, backups and directories can reach every record at once. Keep them on Allow/Deny for production access, and Adaptive MFA for routine logins.

How Spriv works

Strong authentication without slowing down care

Clinicians cannot wait on a code between patients. Spriv verifies the second factor in the background on a trusted workstation and interrupts only when something looks wrong.

STEP 01

Pair the phone once

An administrator adds the user, Spriv sends a pairing link, and the user opens it in the Spriv app on their phone.

STEP 02

Approve the first login

The first sign-in from a workstation is approved on the phone. Spriv records that computer with the environment the phone reports.

STEP 03

Routine logins clear silently

When the workstation and phone match, access is granted in as little as 175 milliseconds. A new computer or location gets challenged. Windows login MFA.

Privacy by design

No PHI goes to Spriv

Spriv checks identity, not records. It confirms that the phone and the computer are in matching locations and never shares the phone's actual location. Zero personally identifiable information is transferred.

Whether you need a business associate agreement with any vendor is a determination for your privacy officer or counsel.

  • Lost phone

    An administrator swaps the phone in the management portal in under a minute. Account recovery

  • Forgotten phone

    An administrator can postpone the second factor for up to 72 hours. Document and approve it as an exception.

  • Staff leaving

    Set the user to Deny or Locked in the control panel so their phone stops working as a factor.

Questions

HIPAA two factor authentication questions

If HIPAA does not name MFA, why deploy it now?

Because the authentication and risk analysis standards already apply, and stolen credentials are a common way into healthcare systems. MFA is a direct, documentable answer, and it gets you ahead of the proposed update if it is finalized.

Is Spriv HIPAA certified?

There is no official HIPAA certification for products. Spriv's MFA is built to satisfy HIPAA's authentication expectations and helps you meet them; your compliance program decides the rest.

What if a clinician's phone has no signal?

TOTP codes are generated on the phone every 30 seconds and work with no internet or carrier signal, which suits basements, imaging suites and other dead zones.

Does Spriv log users out of shared computers?

Spriv's continuous authentication detects when the user has left the authorized computer and tells your platform, which can then end the session. It can support your automatic logoff procedures; it does not replace them.

Checkit!

Protect ePHI access in the background

Two free users and two free servers, no credit card. Install on a clinical server in under five minutes.