We walked into a six-provider practice last year to look at their billing and noticed three things before we opened a report. The two front desk workstations were logged into the practice management system as "frontdesk." The clearinghouse password was on a yellow note under the keyboard. And the office manager's email, which received every remittance notice and every payer letter, had no second factor. She had been meaning to turn it on.

Nothing had gone wrong yet, which is the state most practices are in. HIPAA multifactor authentication requirements are about to become explicit, but the current Security Rule already forbids two of the three things we saw, and the third is the single control that would have stopped the largest healthcare cyberattack in U.S. history. When UnitedHealth's chief executive testified before Congress on May 1, 2024 about the Change Healthcare attack, he said the attackers got in with stolen credentials on a remote access portal that did not have multifactor authentication turned on.

This piece is for the practice owner or manager who is not a technologist: what the rules require now and what is proposed, why shared logins are a compliance problem and not just a bad habit, how a password manager and multifactor authentication fit together, and a four-week plan to put both in place.

Key takeaways

  • The current HIPAA Security Rule requires unique user identification and person or entity authentication; a shared login fails the first one today, before any new rule takes effect.
  • HHS proposed on January 6, 2025 to make multifactor authentication an explicit requirement for systems holding electronic protected health information; as of May 2026 the rule is not final, but the direction is settled and payers and cyber insurers are already asking.
  • A password manager is what makes unique, long, unrepeated passwords workable for a staff of eight sharing forty logins; MFA is what makes a stolen password insufficient.
  • Email, remote access, the EHR and practice management system, the clearinghouse and the bank are the five places to turn MFA on first, in that order.

What the rules say now, and what is coming

Three provisions of the Security Rule at 45 CFR 164 matter here. Unique user identification (164.312(a)(2)(i)) is a required implementation specification: each user must have a unique name or number so their activity can be tracked. Person or entity authentication (164.312(d)) is a required standard: the practice must verify that the person seeking access is who they claim to be. Password management (164.308(a)(5)(ii)(D)) is an addressable specification: procedures for creating, changing and safeguarding passwords, or a documented reason why an alternative is equivalent. None of these say the word "multifactor," which is why practices have treated MFA as optional. They do say that "frontdesk" logged in for the whole day is not compliant, because no one can tell who did what.

On January 6, 2025, HHS published a notice of proposed rulemaking to update the Security Rule for the first time since 2013. Among other changes, it would remove the distinction between required and addressable specifications, require multifactor authentication for access to systems containing electronic protected health information with narrow exceptions, require encryption at rest and in transit, require an asset inventory and network map, and require annual compliance audits. The comment period closed March 7, 2025. As of May 2026 the rule has not been finalized, and the federal regulatory agenda has pushed the target date out more than once. We think practices should act as though it were final, for two reasons: HHS's voluntary Cybersecurity Performance Goals, published in January 2024, already list MFA among the ten essential goals, and cyber insurance applications have been asking "do you enforce MFA on email and remote access" for several years, with a "no" raising the premium or voiding the coverage.

Why shared logins are the first thing to fix

A shared login is the most common Security Rule violation we see, and it is usually invisible to the people doing it because it is convenient and everyone is trusted. The compliance problem is the audit trail. If a patient complains that someone looked at her record, or if OCR asks who accessed a chart, "frontdesk" is not an answer. The operational problem is worse: when a staff member leaves, you cannot remove her access without changing a password everyone uses, so in practice nobody changes it, and a former employee has working credentials for months.

Payer portals add a contractual layer. Most clearinghouse and payer portal terms require one account per individual user and prohibit sharing. A practice sharing one Availity login among four billers is in breach of terms it agreed to, and a suspended account stops eligibility checks and claim status lookups for the whole office.

The fix costs nothing but administrator time: one account per person on every system that touches patient or payment data, including per-diem staff. Where a vendor charges per user, ask about read-only or limited roles for occasional users rather than sharing.

Password managers: what they solve

Once every person has their own login on every system, an eight-person practice has somewhere between 60 and 120 credentials, and no one can remember 12 distinct strong passwords. Without a tool, staff reuse one password everywhere or write them down. A password manager is an encrypted vault that generates a long random password for each site, stores it, fills it in, and shares specific entries with specific colleagues without revealing them. Business editions add an administrator console: the practice owns the vault, can see which accounts each employee holds, and can revoke a departing employee's access in one step.

The current federal guidance on passwords supports this approach. NIST's Digital Identity Guidelines, revised in 2025 as SP 800-63B Revision 4, favor length over complexity, recommend screening new passwords against lists of known compromised passwords, drop mandatory periodic changes in favor of changing on evidence of compromise, and expect systems to allow pasting from a password manager. Practically, that means your policy can say: unique password per system, generated by the manager, at least 15 characters, changed when a breach notice arrives, and no sticky notes. It also means the quarterly forced-change rule many practices still enforce is doing more harm than good, because it pushes people toward predictable variations.

Use shared vaults only for credentials that genuinely belong to the practice rather than a person: the domain registrar, the website host, a vendor account with a single seat. Limit each to two named people and log who opened it. Never put a credential in an SOP document, a spreadsheet or a group text.

Multifactor authentication: where and which kind

Multifactor authentication means proving identity with two different kinds of evidence: something you know (the password) plus something you have (a phone app, a hardware key) or something you are (a fingerprint). A stolen password alone then gets the attacker nothing. Not all second factors are equal. A code sent by text message can be intercepted or socially engineered away from a phone carrier; an authenticator app that generates a rotating six-digit code is better; a push notification with number matching is better still; a hardware security key or a passkey is phishing-resistant, because it will not work on a fake login page. For a small practice, authenticator apps on staff phones (or practice-issued phones for those who object) are the reasonable middle, with hardware keys for the two or three administrator accounts.

OrderSystemWhy it comes firstWhat to turn on
1Email (Microsoft 365, Google Workspace)Password resets for every other system land here; remittance notices and payer letters live hereMFA for every mailbox, no exceptions; block legacy protocols that bypass it
2Remote access: VPN, remote desktop, EHR remote clientThe Change Healthcare entry point; reachable from anywhere by anyoneMFA on the gateway itself, not just the application behind it
3EHR and practice management systemHolds the protected health information the Security Rule is aboutVendor MFA, or single sign-on through the email provider with MFA
4Clearinghouse and payer portalsClaims, remittances, eligibility, bank details for EFTVendor MFA; most large portals now offer or require it
5Bank and payrollWhere the money is; EFT redirection fraud starts with these loginsBank-issued token or app; dual approval for any payee change

Medicare's own systems have already made the move. PECOS and the other CMS provider portals require identity verification and MFA through Login.gov or ID.me, so any practice that enrolls providers is already using MFA somewhere. The task is extending the same habit to the systems the practice controls.

The 30-day plan

  1. Week 1, inventory. List every system that holds patient, payment or credential data, who has access, and whether any login is shared. Expect 12 to 20 systems in a small practice. Create individual accounts for every shared login and retire the shared one at the end of the week.
  2. Week 2, password manager. Choose a business edition, set up the administrator console with two administrators, create a vault per person and two or three shared vaults, and spend 20 minutes with each employee moving their credentials in and generating new passwords for the weakest ones. Write the password policy the same week.
  3. Week 3, MFA on email and remote access. Enable it tenant-wide, help each person enroll an authenticator app, issue hardware keys to administrators, and disable any legacy mail protocol that lets a password alone through.
  4. Week 4, MFA on the rest, and offboarding. Turn on MFA in the EHR, practice management system, clearinghouse, portals and bank. Write the offboarding checklist: on the last day, disable the email account, revoke the password manager seat, remove each system login, and record the date. Update the security risk analysis to reflect all of it.

The cost is modest: business password managers are priced per user per month, authenticator apps are free, and hardware keys are a one-time purchase for a few people. The time is the real investment, roughly two hours per employee across the month. Our technology team sees the same pattern everywhere: the first week is the hard one, and by week four staff wonder why it took so long.

Questions we hear

Our EHR vendor says MFA is "on the roadmap." What do we do in the meantime?

Put MFA in front of it. If staff reach the EHR through a remote desktop or a VPN, MFA on that gateway covers the EHR behind it. If the EHR is a web application, ask whether it supports single sign-on through Microsoft or Google, which brings your email MFA with it. Document the vendor's answer and date in your risk analysis; it shows a regulator you identified the gap and compensated for it.

A physician refuses to use an app on his personal phone. Is that a valid exception?

It is a valid preference and an invalid exception. A hardware security key on his badge lanyard, a practice-issued phone or an authenticator on his workstation all work. A login without a second factor for the person with the widest access in the building does not.

Is MFA required by HIPAA today or not?

Not by that name, today. The Security Rule requires you to authenticate users and address password management, and a risk analysis that leaves email and remote access reachable with a password alone would be hard to defend in 2026. The proposed rule would make MFA explicit, and HHS's 2024 performance goals already call it essential. The practice waiting for the final rule will be doing this under a deadline.

What to do this week

  1. Walk the office and list every shared login you can find, including the ones on sticky notes and in the "passwords" spreadsheet.
  2. Turn on MFA for the practice's email tenant today; it is the single highest-value change and takes an afternoon.
  3. Pick a business password manager and enroll the manager and one administrator to learn it before rolling it out.
  4. Check your cyber insurance application from last renewal and see what you attested about MFA; make it true.
  5. Put the four-week plan on the calendar with names next to each week and a date for updating the risk analysis at the end.