Authentication

Authentication, required in policy and tracked per vendor

A composed authentication policy requiring MFA and per-person credentials, plus a running check on whether every PHI vendor's authentication attestation is current.

The rule does not name a method, which is why so many clinics stop at “MFA isn’t required.” That sentence is true and does nothing for you. The question is what you decided, and whether you can show it.

The policy is composed from your clinic’s facts

Your authentication policy is generated against your recorded facts. It requires verifying identity before access, per-person credentials with no sharing, MFA on systems holding PHI, and separate phishing-resistant accounts for privileged access. It ties credential creation and removal to your workforce authorization and termination policies, so the three move together rather than drifting apart.

It records the sign-in method and strength per system, and requires per-vendor authentication evidence refreshed yearly. Conditional clauses handle high turnover, field sign-in, parent portal sign-in, and shared devices.

What gets tracked after the policy exists

Six requirements, each holding or not:

  • The policy is active and reviewed within the last twelve months.
  • Every vendor recorded as touching PHI has a current authentication attestation on file.
  • The platform’s own MFA is attested.
  • The policy is adopted, and its facts have not drifted.

What this is, and what it is not

The system tracks whether the MFA decision is recorded and whether your vendors have attested to their authentication controls. It does not test a login, check whether MFA is switched on in any system, or find shared credentials. The MFA signal is an attestation on file, not a live reading of your tenant’s settings.

What that gives you is the document an investigator asks for: a policy that requires MFA, a record of the decision, and vendor attestations backing it. What it does not give you is an excuse to skip actually turning MFA on.

What an investigator gets

A dated, adopted policy requiring per-person credentials and MFA on PHI systems. Current authentication attestations from every vendor touching PHI. A record tying credential lifecycle to your authorization and termination procedures.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.