Imaging device still on factory password
A PACS modality admin account used the vendor default. Attackers scanned it from a mis-segmented VLAN. IA-5 onboarding checklist forces password change and inventory of device authenticators before go-live.
IA-5 requires managing information system authenticators by verifying identity before enrollment, establishing initial authenticator content, ensuring adequate strength, establishing refresh/loss/compromise procedures, protecting authenticator feedback, and changing default authenticators. Passwords, MFA devices, certificates, passkeys, and API keys that protect ePHI all fall here.
Keep authenticators strong, secret, and lifecycle-managed so stolen or default credentials cannot silently unlock systems with ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
A PACS modality admin account used the vendor default. Attackers scanned it from a mis-segmented VLAN. IA-5 onboarding checklist forces password change and inventory of device authenticators before go-live.
An admin approves endless push prompts and gets phished. IA-5 + IA-2 move admins to number-matching or FIDO2 keys and train on prompt bombing.
A developer commits an interface engine API key. Secret scanning + IA-5 rotation procedures revoke and re-issue the key, and block future commits of secrets.
Expect questions about default passwords on clinical devices and how MFA resets are verified. Authenticator weaknesses often appear in penetration test reports — map remediations to IA-5.
How this NIST control supports HIPAA Security Rule expectations.
Modern NIST guidance favors long passwords, breach detection, and change-on-compromise over arbitrary frequent rotation. Document your approach in policy.
Push can be phished via fatigue. Prefer phishing-resistant authenticators for privileged ePHI administration.
Yes. Manage issuance, storage, rotation, and revocation like other authenticators.
Related controls that commonly accompany IA-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.