Multi-Factor Authentication (MFA)
Also known as: MFA, Multifactor authentication
Requiring two or more independent factors to verify a user's identity.
Multi-Factor Authentication (MFA) requires a user to present two or more independent credentials, typically something they know (a password), something they have (a device or token), or something they are (a biometric), before access is granted.
While HIPAA does not name MFA explicitly, it is a widely expected control for satisfying authentication requirements and protecting ePHI, because it dramatically reduces the risk from stolen or guessed passwords. But MFA is only as strong as the software that enforces it. Joomla patched four MFA bypasses in 2026, and our Joomla HIPAA compliant guide lists them. Whether HIPAA requires MFA today, and what the proposed 2027 rule changes, is covered in HIPAA MFA requirements.