Get Demo
↑

HIPAA MFA Requirements: Current Rule vs 2025 NPRM Proposal

MFA is not a standalone Required Security Rule standard today — Jan 2025 NPRM proposed MFA; prepare without claiming it is already mandatory.

Published: September 2026 Compliance · HIPAA 8–12 min read

Search results often claim “HIPAA now requires MFA.” Under the current Security Rule there is no standalone MFA implementation specification labelled Required. MFA typically supports Access Control (§164.312(a)) and Person or Entity Authentication (§164.312(d)) as a reasonable and appropriate control. The January 2025 NPRM proposed explicit MFA expectations — not final as of 2026.

Related: HIPAA hub · Security Rule update · §164.312.

Security Rule NPRM — not final: Jan 6, 2025 NPRM (RIN 0945-AA22, 90 FR 898) proposed MFA and related enhancements. No final rule as of September 2026; Unified Agenda projects ~July 2027 (planning estimate). MFA is not a current standalone required Security Rule standard.

§164.312 Technical Safeguards — Standards: Access Control (a), Audit Controls (b) Required, Integrity (c), Person/Entity Authentication (d) Required, Transmission Security (e). Implementation specifications under each standard are Required or Addressable as listed in the regulation.

Today’s Legal Frame

Programme Guidance

  1. Require MFA for remote access to ePHI systems and for privileged accounts.
  2. Prefer phishing-resistant factors where feasible for high-risk roles.
  3. Log MFA success/failure into your audit-control pipeline (§164.312(b)).
  4. Document MFA coverage gaps in the risk analysis and remediation plan.

How CyberSilo Helps

Deploy MFA as Risk Control, Track NPRM Readiness

Authenticate ePHI access strongly today and keep evidence ready if MFA becomes explicitly required.

Frequently Asked Questions

Does HIPAA require MFA today?

There is no standalone Required MFA specification in the current Security Rule. Authentication is Required (§164.312(d)); MFA is widely appropriate. The 2025 NPRM proposed MFA — not final as of 2026.

Where should MFA be applied first?

Remote access to ePHI, privileged/admin accounts, EHR and billing portals, and any cloud console holding ePHI.

How does MFA relate to OCR audits?

OCR frequently examines access controls and authentication. Document MFA coverage and exceptions in your risk analysis and policies.

HIPAA hub · Encryption · Audit logs · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!