Skip to main content
Security Safeguards

Multi-Factor Authentication (MFA)

Requiring two or more independent factors to verify a user's identity.

Multi-Factor Authentication (MFA) requires a user to present two or more independent credentials, typically something they know (a password), something they have (a device or token), or something they are (a biometric), before access is granted.

While HIPAA does not name MFA explicitly, it is a widely expected control for satisfying authentication requirements and protecting ePHI, because it dramatically reduces the risk from stolen or guessed passwords. Whether HIPAA requires MFA today, and what the proposed 2027 rule changes, is covered in HIPAA MFA requirements.

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.