Nursing station shoulder surf
A visitor behind the desk sees a clear password field during unlock. IA-6 masking and privacy screens reduce opportunistic capture.
IA-6 requires obscuring feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals. Unmasked passwords on nursing-station EHR logins, shared kiosks, and projected training demos are a frequent shoulder-surfing and recording risk around ePHI.
Ensure authenticators (passwords, PINs, recovery codes) are not displayed in clear text during authentication to ePHI systems, reducing observation and capture risk in clinical environments.
How this control shows up in healthcare and HIPAA-covered environments.
A visitor behind the desk sees a clear password field during unlock. IA-6 masking and privacy screens reduce opportunistic capture.
Analyst shares EHR login troubleshooting. Policy requires blanking the password field and using remote tools that do not echo secrets.
Instructor types into a projected login. IA-6-aligned demo accounts and masking prevent real authenticator exposure in classrooms.
Simple to test on walkthroughs: watch a login. Clear-text password fields in clinical areas are easy findings tied to access control and workstation security.
How this NIST control supports HIPAA Security Rule expectations.
Not automatically — but in shared clinical areas you should restrict or warn; the control requires obscuring feedback to protect against exploitation.
IA-6 focuses on authenticator feedback during entry; enumeration-safe messaging is good practice aligned with related IA controls.
Yes where PINs can be observed — use shielded pads or layout that reduces observation in public registration areas.
Related controls that commonly accompany IA-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.