Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Multi-Factor Authentication

Multi-factor authentication (MFA) is a multi-step login process that requires users to provide more than just a password to verify their identity. MFA increases security levels by requiring users to present a combination of two or more credentials.

There are three main types of MFA: something you know (passwords, PINs); something you have (cell phone, key); and something you are (biometric – fingerprint, retina scan).

Password theft is ever-evolving and becoming more sophisticated all the time from keylogging, phishing, smishing and pharming. Depending on your organization’s password policies this may be a no-brainer for a hacker: weak passwords, shared/generic passwords, or no password policies at all.

MFA is essential to web security because it immediately neutralizes the risks associated with compromised passwords. If a password is hacked, guessed, or even phished, that’s no longer enough to give an intruder access: without approval at the second factor, a password alone is useless.

The HIPAA Rule does not mandate MFA be in place; however, its presence will show State and government entities the organization’s compliance with identity and access management for PHI, ePHI, sensitive data including employee personally identifiable information (PII).

By implementing MFA in healthcare settings, organizations can significantly reduce the risk of unauthorized access to patient data.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author:

Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP