← Back to Blog

Not All MFA Is Equal: Phishing-Resistant Authentication for Healthcare

You Did the Right Thing. Now Do It Well.

If you have turned on multi-factor authentication across your practice, you have already done the single most valuable thing on any security checklist. MFA is what makes a stolen password insufficient on its own, and it is the reason it appears at the top of every list of controls that actually prevent breaches. This post is not here to talk you into MFA — it is here to make sure the MFA you have is the kind that holds up against how attackers actually operate in 2026. Because not all second factors are created equal, and the gap between them is exactly where the more determined attackers now live.

The MFA Methods, From Weakest to Strongest

"MFA is on" can mean very different things. Here is the practical hierarchy:

  • SMS text codes. Better than nothing, and a real improvement over a password alone — but the weakest common method. Codes can be phished (a fake login page asks for the code and relays it instantly), and phone numbers can be hijacked through SIM-swapping. If this is all you have, keep it, but plan to move up.
  • Authenticator app codes. The six-digit rotating codes from an app are a solid step up — immune to SIM-swapping. But they are still phishable: a convincing fake page can capture the code and use it within its short validity window.
  • Push notifications. "Approve this sign-in?" prompts are convenient, but they introduced a new weakness: MFA fatigue. Attackers with a stolen password spam approval requests until a tired or confused user finally taps "approve." Number-matching variants (type the number shown on screen) blunt this, and are worth enabling where offered.
  • Phishing-resistant authentication. The strongest tier — hardware security keys and device-bound passkeys built on the FIDO2/WebAuthn standard. These are cryptographically tied to the real website, so a fake login page simply cannot complete the authentication. There is no code for a user to be tricked into typing, because there is no code. This is the category that defeats the credential-relay attacks the others are vulnerable to.

Why "Phishing-Resistant" Is the Phrase That Matters

The thread running through the weaker methods is that they all rely, at some point, on a human relaying a secret — a code, an approval — that an attacker can intercept or socially engineer. Phishing-resistant methods remove the human-relayed secret entirely. The authentication is a cryptographic handshake between your device and the genuine service, bound to the real domain. A user standing on a perfect replica of your EHR login page cannot hand over anything useful, because the security key will refuse to authenticate to the wrong site. It is the difference between teaching people not to fall for fakes and making the fakes structurally incapable of working.

This is also the direction regulators are pointing. The proposed Security Rule updates would move MFA from an addressable consideration to an explicit requirement for healthcare. Adopting strong MFA now is not just better security — it is getting ahead of where the rules are clearly headed.

Upgrading Without Disrupting the Clinic

The objection is always operational: clinical staff move fast, share workstations, and cannot tolerate friction at the point of care. Fair — but upgrading MFA does not have to mean grinding the clinic to a halt. A few principles keep it practical:

  • Protect the crown jewels first. You do not have to convert everything at once. Start with the highest-risk access: email, remote/VPN access, and administrative consoles. These are where a compromise does the most damage, and where stronger MFA pays off fastest.
  • Match the method to the setting. Hardware security keys suit administrators and remote workers. Passkeys on a known device suit individual staff logins. For shared clinical workstations, look at badge-tap or proximity solutions that pair fast re-authentication with strong identity.
  • Keep a tested recovery path. Lost keys and replaced phones are inevitable. Define — and test — a secure account-recovery process before rollout, so a lost factor does not become either a lockout or a backdoor.
  • Phase it, and bring staff along. Roll out by group, explain why in plain terms (it is faster than a breach), and fold the message into your ongoing security training. Adoption is a change-management problem as much as a technical one.

The Bottom Line

Any MFA beats a password alone, so if you are starting from nothing, turn something on today. But if you already have MFA, the next move is not to relax — it is to ask which kind you have, and to push your most sensitive access toward phishing-resistant methods that modern attacks cannot defeat. The attackers have adapted to the weaker forms. Staying a step ahead means your second factor is one they cannot phish, relay, or fatigue their way past.

Related Reading

Call to Action

Not sure whether your current MFA would survive a real phishing attack? Schedule a walkthrough to see how HIPAA Security Suite helps you assess and strengthen authentication across your practice, or take the 3-minute readiness quiz to find your highest-priority gaps.

Ready to simplify your HIPAA compliance?

See how HIPAA Security Suite can protect your organization.

Request a Demo