Impossible travel to EHR
User authenticated in Ohio then attempts EHR from overseas minutes later; IA-10 adaptive policy demands step-up and SOC review.
IA-10 requires individuals and/or devices to satisfy additional authentication requirements based on organization-defined circumstances or risk indicators. Healthcare IdPs can step up MFA, block, or challenge when clinicians or admins attempt EHR access from new countries, jailbroken devices, or impossible travel patterns.
Apply additional authentication or blocking when defined risk circumstances are detected for users/devices accessing ePHI systems.
How this control shows up in healthcare and HIPAA-covered environments.
User authenticated in Ohio then attempts EHR from overseas minutes later; IA-10 adaptive policy demands step-up and SOC review.
Coder’s first login from unknown laptop requires device registration plus MFA before VDI with ePHI opens.
Requesting domain admin triggers additional authentication and PAM checkout beyond standard network login.
IA-10 evidence is conditional authentication policies—not static MFA alone.
How this NIST control supports HIPAA Security Rule expectations.
MFA is baseline; IA-10 adds circumstance-based additional requirements.
Tune carefully—use device compliance and role-aware policies; avoid crude geo blocks on roaming specialists without alternatives.
IA-2 covers authenticator types; IA-10 adapts requirements based on risk circumstances.
Related controls that commonly accompany IA-10.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.