IA-6 Identification and Authentication

Authenticator Feedback

Medium Risk Easy Low Cost

IA-6 requires obscuring feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals. Unmasked passwords on nursing-station EHR logins, shared kiosks, and projected training demos are a frequent shoulder-surfing and recording risk around ePHI.

Control Objective

Ensure authenticators (passwords, PINs, recovery codes) are not displayed in clear text during authentication to ePHI systems, reducing observation and capture risk in clinical environments.

Implementation Guidance

  1. Configure EHR, VPN, email, and clinical apps to mask password/PIN entry by default.
  2. Disable show-password where policy forbids it in shared clinical areas; if allowed, time-limit and warn.
  3. Ensure error messages do not unnecessarily reveal which authenticator factor failed beyond org policy.
  4. Prohibit clear-text authenticators in screenshots used for training; use redaction.
  5. Review thin-client and kiosk browsers for autofill displaying secrets.
  6. Cover mobile EHR apps and MFA prompt UX.
  7. Test projector/meeting share scenarios used by trainers and support.
  8. Include BA-hosted portals that workforce use for ePHI.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nursing station shoulder surf

A visitor behind the desk sees a clear password field during unlock. IA-6 masking and privacy screens reduce opportunistic capture.

Helpdesk screen-share

Analyst shares EHR login troubleshooting. Policy requires blanking the password field and using remote tools that do not echo secrets.

Training deck with live demo

Instructor types into a projected login. IA-6-aligned demo accounts and masking prevent real authenticator exposure in classrooms.

Best Practices

  • Default masking on all ePHI app logins.
  • Restrict show-password in shared spaces.
  • Redact secrets in training materials.
  • Review kiosk/browser autofill behavior.
  • Include mobile and BA portals.
  • Pair with privacy screen standards where needed.

Common Gaps & Violations

  • Legacy apps displaying passwords in clear text.
  • Training screenshots with real passwords.
  • Shared workstations with visible remembered passwords.
  • Overly verbose auth error messages.
  • Unmasked PINs on medical device consoles.

Required Documentation

  • Authenticator feedback standard (IA-6)
  • Application configuration baselines for login UX
  • Exceptions for accessibility with compensating controls
  • Training material redaction guidance
  • Sample hardened login screenshots (fake data)

How to Test & Validate

  1. Sample EHR and VPN logins; confirm masking.
  2. Check clinical kiosks for clear-text autofill.
  3. Review training content for exposed secrets.
  4. Test a BA portal used by billing staff.
  5. Verify device console PIN entry behavior where feasible.

Audit Considerations

Simple to test on walkthroughs: watch a login. Clear-text password fields in clinical areas are easy findings tied to access control and workstation security.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a) Access Control — unique user identification depends on protected authenticators.
  • 164.312(d) Person or Entity Authentication — authentication must not unnecessarily expose credentials.
  • 164.308(a)(5) Security Awareness — workforce should avoid exposing passwords in shared spaces.
  • 164.530(c) Safeguards — reasonable safeguards include preventing casual observation of credentials that protect PHI.

Compliance Tips

  • Add IA-6 checks to application security baselines before go-live.
  • Include password-field checks in clinic security walkthroughs.
  • Prefer password managers that fill without lingering clear text on shared PCs.

Frequently Asked Questions

Does a show-password eye icon violate IA-6?

Not automatically — but in shared clinical areas you should restrict or warn; the control requires obscuring feedback to protect against exploitation.

Are account lockout messages in scope?

IA-6 focuses on authenticator feedback during entry; enumeration-safe messaging is good practice aligned with related IA controls.

Do smart-card PIN pads need masking?

Yes where PINs can be observed — use shielded pads or layout that reduces observation in public registration areas.

References & Resources

  • NIST SP 800-53 Rev. 5 — IA-6
  • Related controls: IA-5, IA-2, AC-11, SC-4

Need Help Implementing IA-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.