Ready to transform your IT experience? Reach out to our experts to discuss how our tailored solutions can meet your business needs and keep your technology running smoothly.
MFA Is Becoming Mandatory Under HIPAA: Here's What Changes in 2026
Not by name, not yet. HIPAA's current Security Rule doesn't require multi-factor authentication (MFA) as a standalone rule. But a proposed 2026 update from HHS's Office for Civil Rights would make MFA mandatory for any system that touches electronic patient data, closing the loophole that let practices skip it. The proposal is still pending, not final.
That matters for every covered entity and business associate, which in practice means nearly every medical, dental, or therapy office handling patient records. This guide covers the real HIPAA MFA requirements for 2026: what's changing, which systems to prioritize first, what a rollout costs a small practice, and what it looks like once you're past the policy document and into actual staff training.
What Is Changing in the 2026 HIPAA Security Rule?
HHS’s Office for Civil Rights issued its Notice of Proposed Rulemaking (NPRM) on December 27, 2024, and published it in theFederal Register on January 6, 2025. The 60-day public comment period closed March 7, 2025, and as of this writing, the rule is still proposed. It hasn’t been finalized.
This is the first major overhaul of the Security Rule’s technical requirements in over two decades, and the mechanism is simple to describe even though the proposed rule itself runs long. It eliminates the “addressable versus required” distinction that has defined HIPAA compliance since 2003.
Under the current rule, safeguards like MFA fall into a gray zone called “addressable.” A practice can look at an addressable safeguard, decide it isn’t necessary for its situation, document that reasoning, and skip it. The proposed rule removes that flexibility. If it’s finalized as written, regulated entities would get 60 days after the rule’s effective date, then a 180-day window to come into compliance. Multi-factor authentication moves from something a practice could justify skipping to something every regulated entity has to implement, with only narrow, documented exceptions.
Is MFA Required for HIPAA Compliance Right Now?
Here’s where a lot of guidance online gets sloppy, so let’s be precise. Today, MFA is not named as a required control anywhere in the current HIPAA Security Rule. That doesn’t mean you’re free to skip it.
OCR auditors already treat MFA as a baseline “reasonable and appropriate” safeguard under the existing rule’s general requirements, particularly for email and remote access. In our experience supporting Pasadena and Los Angeles healthcare clients through security assessments, MFA is one of the first things an auditor or a cyber-insurance underwriter asks about, whether or not it’s named explicitly in the rule text. We treat it as HIPAA-focused IT security work that practices need regardless of how the final rule shakes out, because the underlying risk isn’t going away.
That risk is well documented. Passwords alone fail constantly because of how attackers reuse stolen credentials harvested from breaches at completely unrelated companies. A practice’s own password policy does nothing to stop a front-desk login that shares a password with some retailer’s site that got breached two years ago.
What Actually Counts as Multi-Factor Authentication?
The Cybersecurity and Infrastructure Security Agency (CISA) defines MFA as proving your identity with at least two of three factor types: something you know (a password or PIN), something you have (a phone, an authenticator app, or a physical security key), and something you are (a fingerprint or face scan). A password alone is only “something you know,” which is exactly why it’s easy to defeat once an attacker gets hold of it, whether through phishing or how quickly a weak password gets cracked with automated tools.
Not all MFA is equally strong, either. Text message codes technically qualify as a second factor, but NIST’s updated digital identity guidelines now classify SMS as a “restricted authenticator.” It’s still allowed, but it carries known weaknesses like SIM-swapping and number porting that authenticator apps and hardware security keys simply don’t have. For anything touching patient data, those stronger methods are the better standard.
Which Systems Need MFA First?
You don’t have to flip the switch on every system on day one. Prioritize by risk. Email and remote access are almost always the first place attackers try, and they’re also where Microsoft 365 security hardening makes the biggest immediate difference for most of the practices we work with.
| System Type | Example | Priority |
|---|---|---|
| Microsoft 365, Google Workspace | High | |
| EHR / practice management | Patient charting, scheduling, billing | High |
| Remote access | VPN, remote desktop into the practice network | High |
| Admin / privileged accounts | Practice management admin console, backup systems | High |
| Cloud storage | SharePoint, OneDrive, Dropbox holding records | Medium |
What Does This Actually Cost a Small Practice, and How Long Does It Take?
Cost is the question almost nobody answers honestly, mostly because most of what’s written targets hospital systems with six-figure security budgets. A 10-to-40-person practice is a different animal.
Here’s the good news: authenticator apps (Microsoft Authenticator, Duo, Google Authenticator) are free. The real line item is hardware security keys for the handful of privileged accounts, like the practice owner, office manager, or billing admin, where you want the strongest protection available. Based on current retail pricing, FIDO2-certified security keys run roughly $25 to $50 each. Outfitting five to ten privileged accounts typically lands in the low hundreds of dollars in tools, not thousands.
| Rollout Phase | Typical Duration | What It Involves |
|---|---|---|
| System inventory | 3 to 5 days | Map every system that touches ePHI |
| Priority rollout | 1 to 2 weeks | Enable MFA on email, EHR, and remote access first |
| Full staff rollout | 2 to 4 weeks | Extend to remaining systems, train every user |
| Documentation & review | Ongoing, quarterly | Log exceptions, confirm enrollment, reassess |
For a practice already working with managed IT services in Pasadena for monitoring and patching, an MFA rollout usually folds into existing support instead of becoming its own project. Practices starting from scratch, without an IT partner already in place, tend to land toward the longer end of that timeline.
A Real MFA Rollout: What This Looks Like in Practice
Here’s what nobody’s checklist tells you: the technology part of an MFA rollout is the easy part. The hard part is people.
In our Los Angeles team’s experience rolling this out for small healthcare offices, week one always looks the same. Front-desk staff who’ve shared a single login for the scheduling system for years suddenly each need their own account and their own phone for approval prompts. Someone’s phone is too old to run the authenticator app, and a biller who works from home two days a week needs her own plan too.
None of it is complicated, but all of it needs someone to actually sit with the staff, not just email a policy PDF. We coordinated one recent healthcare IT support in Los Angeles rollout directly around a practice’s EHR vendor’s own MFA settings, since the vendor platform had its own authentication layer separate from email and the network login. That kind of vendor coordination is easy to miss if you’re planning a rollout purely from a compliance checklist instead of from what your actual software stack looks like.
Businesses across Pasadena and Orange County lean on a local managed IT partner for exactly this kind of hands-on rollout support: someone who can sit with the front-desk team on day one, not just ship a policy document.

HIPAA MFA Compliance Checklist for Small Practices
Skip the enterprise audit checklist. This one is scoped to a practice, not a hospital system.
- Inventory every system that creates, receives, maintains, or transmits ePHI, including vendor portals and cloud storage
- Assign MFA methods by role: authenticator apps for general staff, hardware keys for owners and admins
- Start with email, remote access, and your EHR before anything lower-risk
- Document any legacy system that can’t support modern MFA, along with the compensating control you’re using instead
- Set a review cadence (quarterly is typical) to confirm every account is still enrolled
Our IT audit and compliance support team builds this documentation alongside the rollout itself, so a practice isn’t scrambling to reconstruct it later if OCR ever asks.
Beyond HIPAA: What Else Is Pushing You Toward MFA?
HIPAA isn’t the only reason to move on this. Cyber-insurance underwriters increasingly require MFA on email and remote access as a condition of coverage, and some carriers will deny a ransomware claim outright if it wasn’t in place. If your practice also processes card payments, PCI DSS v4.0 has its own multi-factor requirements for anyone with access to the cardholder data environment. AllSafe IT’s layered cybersecurity services cover both angles at once instead of treating HIPAA as an isolated project, and we see the same pattern with IT support for Orange County businesses in financial services, who face nearly identical MFA pressure from their own regulators on a parallel timeline.
How AllSafe IT Helps Pasadena, Los Angeles, and Orange County Practices Meet These Requirements
We’ve been doing IT consulting for Los Angeles businesses for over 20 years, and we’re SOC 2 compliant ourselves, which means we go through the same kind of audit we help your practice prepare for. AllSafe IT has also been named to CRN’s MSP 500 multiple years running, for what that third-party validation is worth when you’re picking a partner.
For practices that want MFA handled as part of an ongoing relationship instead of a one-time project, our virtual CIO services build compliance strategy into regular planning, so the next regulatory update doesn’t catch you flat-footed either.
Frequently Asked Questions
Does HIPAA currently require multi-factor authentication?
Not by name. HIPAA’s current Security Rule doesn’t explicitly require MFA, but OCR and cyber-insurance underwriters already treat it as a baseline “reasonable and appropriate” safeguard. A proposed 2026 update would make MFA an explicit, mandatory requirement, though that rule hasn’t been finalized yet.
What happens if my practice doesn’t have MFA in place when the rule finalizes?
The proposed rule includes a 180-day compliance window after a final rule takes effect, but OCR hasn’t set a finalization date. In the meantime, the bigger practical risk is an OCR investigation after a breach or complaint, where missing MFA gets treated as a missing “reasonable and appropriate” safeguard regardless of the final rule’s status.
Is a text message code good enough for HIPAA MFA?
SMS technically counts as a second factor, but NIST now classifies it as a “restricted authenticator” due to risks like SIM-swapping. It’s better than no MFA at all, but authenticator apps or hardware security keys are the stronger, more future-proof standard for anything touching patient data.
How much does it cost a small practice to set up MFA?
Authenticator apps are free for most staff. Hardware security keys for privileged accounts, like owners and admins, typically run $25 to $50 each at current retail pricing, so outfitting a handful of high-risk accounts usually costs a few hundred dollars in tools, not thousands.
Do I need MFA on every system, or just the ones with patient data?
Scope covers anything that creates, receives, maintains, or transmits ePHI, not just your primary EHR. That includes email, remote access, cloud storage, admin consoles, and any vendor portal that touches patient records, even indirectly, so a full systems inventory matters more than guessing which platforms count.
How long does it take to roll out MFA across a small practice?
For a 10-to-40-person practice, a full rollout typically takes two to six weeks: a few days to inventory systems, one to two weeks to prioritize the highest-risk systems, and the remainder to extend coverage and train staff. That’s a much shorter timeline than the multi-quarter rollouts enterprise organizations often describe.
If your practice is still mapping out what an MFA rollout actually looks like for your systems, that’s exactly the kind of conversation we have with Pasadena, Los Angeles, and Orange County practices every week. No pressure, no jargon, just a clear picture of where you stand and what’s actually worth prioritizing first.


