Cybersecurity: What Every NP Must Know Part 3 – MFA

Staying safe online is a major concern today.

So it’s hard to fathom that the most commonly used password in the country is still 123456?!

That’s according to Cisa.gov (Cybersecurity & Infrastructure Security Agency), whose primary mandate is to coordinate efforts to reduce the risk to US cyber and physical infrastructure.

The organization also provides a range of no-cost cybersecurity services and tools to the public.

If you’ve kept up with our discussions about cybersecurity, you know that the bill is not yet law, but it’s likely it will be soon. The proposed changes are significant, and so it’s reasonable to start preparing for them now.

However, if you’re new to our discussion, you can get up to speed by first reading the overview of the changes, then part 1 (take inventory), here.

Today, we’re tackling a core requirement in the bill: Multi-Factor Authentication (MFA).

Cybersecurity in healthcare is no longer just an IT concern, but is quickly becoming a core business responsibility for practice owners.

We’re moving away from loosely defined “best practices” toward specific, enforceable security expectations.

One of the most important is Multi-Factor Authentication (MFA).

Under HIPAA, practices were expected to evaluate multi-factor authentication (MFA), but not to implement it.

But that’s no longer the case.

As mentioned in previous articles, Senate Bill 3315 proposes baseline security requirements across the entire healthcare industry.

This is in response to large-scale breaches that exposed the interconnected and vulnerable nature of the healthcare system. And so, MFA is no longer optional, but is becoming the default.

You probably know the answer, but to be on the same page, let’s briefly define it.

Here’s CISA once more… “MFA is a layered approach to securing data and applications where a system requires a user to present a combination of two or more credentials to verify a user’s login.”

MFA consists of two or more parts/factors:

  1. Something you know… a password
  2. Something you have… a phone
  3. Who you are… fingerprint, facial, or iris scan

Once set up, the first time you sign in on a device, you must provide your username and password, then verify you have the second factor by entering the code you received.

The next time you sign in on the same device, you still need to provide your username and password. However, you don’t need to verify that you have the second factor, which is stored in a cookie.

This will be valid until the cache is cleared… or the cookies are cleared.

Almost all applications we use day in and day out require MFA, verifying identity via text, phone, email, or another method.

Isn’t it time to implement the same in your office?

Because most cyberattacks don’t start with a sophisticated hack. They start with something much simpler:

  • A never revoked password
  • A reused login
  • A stolen password
  • A phishing email

And no matter the method, once attackers gain access, they can move quickly, often without detection.

But MFA changes the landscape.

By requiring a second form of verification, such as a code on a phone, a login approval, or a physical security key, MFA makes it significantly harder for unauthorized users to gain access, even if they have the correct password.

This is why CISA and NIST (National Institute of Standards and Technology) list MFA among the most effective cybersecurity controls.

Senate Bill 3315 not only proposes stronger cybersecurity but also standardization across key areas that rely directly on MFA, including:

1. Identity and Access Management

Every user accessing systems with patient data must be properly authenticated via MFA, including:

2. Remote Access Security

With telehealth and cloud-based systems, remote access is now a major risk. Hence, MFA is expected for:

  • Remote logins
  • VPN (if used) access
  • Cloud-based platforms

3. Privileged Access Controls

Not all users need the same level of access. Administrators and owners have full access, whereas employees typically do not. This means that MFA should be mandatory for:

  • Practice owners
  • IT administrators
  • Billing system managers

4. Vendor and Third-Party Oversight

Healthcare organizations work with outside vendors, including clearinghouses and software providers. You may be expected to:

  • Confirm vendors use MFA and/or
  • Document their security practices

Too many practices still rely on outdated security measures that will not hold up in the near future, including:

  • Password-only logins
  • Shared staff accounts
  • Shared passwords
  • SMS-only verification (as the sole method)
  • Informal or undocumented security practices

These approaches will not meet new security standards and must be updated as soon as possible.

Document your MFA practices, as potential audits expect written plans, policies, and a list of systems protected by MFA.

Zero Trust Security is the new approach to cybersecurity.

The central premise is to: never trust, always verify.

Therefore, in addition to a login, MFA may also be required:

  • When accessing sensitive data
  • When logging in from a new device
  • When performing high-risk actions

Traditional passwords alone are no longer adequate and are being replaced by various MFA methods.

But not all MFAs are created equal… not all provide the same level of security.

The MFA you choose should be tailored to your specific situation, the required security level, and the user’s workflow.

For example, asking a medical assistant to use SMS or email verification for repeated device access throughout the day may not be the best solution.

The assistant’s workflow may require moving between rooms and accessing different devices, with little time to spare in between.

Using SMS or email verification might slow down the workflow, as employees have to re-enter their email address or wait for a text to confirm their identity when moving between devices.

Using biometric authentication, such as a fingerprint or facial recognition, might be a better solution in this scenario.  

Today, we have numerous MFA solutions to choose from, meeting the needs of varying environments and workflows.

  • Biometrics: fingerprint, facial recognition, or iris scan to log in
  • Authenticator apps: provide a temporary, time-sensitive code
  • SMS/Email verification codes: active for a limited duration
  • Push Notifications: sent to a device for approval or denial
  • Physical Security Keys/Hardware Tokens: tap or plug in to verify access
  • Passkeys: encryption using a public and private key

MFA is one of the simplest and most cost-effective security upgrades you can make.

  • Start with the essentials:
    Enable MFA on email, EHR, and billing systems
  • Choose user-friendly tools:
    Physical Security Keys, authenticator apps, or push notifications work well in busy clinical settings. Keep it simple so that MFAs are used and respected.
  • Strengthen over time:
    Add device-based controls or hardware keys for higher-risk accounts as you strengthen your office’s cybersecurity.

While cybersecurity can feel overwhelming and too technical for some Nurse Practitioners, it doesn’t have to be.

MFA is a relatively simple approach that you and your staff are already using everywhere else. Choose a solution that fits your office, workflow, and budget.

MFA, when implemented and used correctly, is easy to understand and effective, enabling you to prevent breaches rather than react to them.

The bottom line is this…

In the future, you must be able to prove that the person accessing your systems is an authorized user and who they say they are… And that’s what MFA provides for your business.

We’ll cover how to implement the new requirements in subsequent articles. And, we’ll keep you up to date on changes to the legislation as soon as information becomes available.


Which MFA tool are you using in your practice? Have you worked with other tools in the past? Which factors did you consider before you picked one tool over the other?

Please share your experiences with us in the comment section below…


By Johanna Hofmann, MBA, MAc., EAMP; regular contributor to the NPBusiness blog.

Leave a Reply


Your email address will not be published. Required fields are marked

This site uses Akismet to reduce spam. Learn how your comment data is processed.

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}