A composed authentication policy requiring MFA and per-person credentials, plus a running check on whether every PHI vendor's authentication attestation is current.
The rule does not name a method, which is why so many clinics stop at “MFA isn’t required.” That sentence is true and does nothing for you. The question is what you decided, and whether you can show it.
Your authentication policy is generated against your recorded facts. It requires verifying identity before access, per-person credentials with no sharing, MFA on systems holding PHI, and separate phishing-resistant accounts for privileged access. It ties credential creation and removal to your workforce authorization and termination policies, so the three move together rather than drifting apart.
It records the sign-in method and strength per system, and requires per-vendor authentication evidence refreshed yearly. Conditional clauses handle high turnover, field sign-in, parent portal sign-in, and shared devices.
Six requirements, each holding or not:
The system tracks whether the MFA decision is recorded and whether your vendors have attested to their authentication controls. It does not test a login, check whether MFA is switched on in any system, or find shared credentials. The MFA signal is an attestation on file, not a live reading of your tenant’s settings.
What that gives you is the document an investigator asks for: a policy that requires MFA, a record of the decision, and vendor attestations backing it. What it does not give you is an excuse to skip actually turning MFA on.
A dated, adopted policy requiring per-person credentials and MFA on PHI systems. Current authentication attestations from every vendor touching PHI. A record tying credential lifecycle to your authorization and termination procedures.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.