Patient portal account takeover
Attackers spray passwords against the portal. IA-8 improvements add MFA, lockout (AC-7), and breached-password checks so a reused consumer password alone cannot open labs and visit notes.
IA-8 requires uniquely identifying and authenticating non-organizational users or processes acting on their behalf. Unlike IA-2 (workforce), this covers patients on portals, external referring providers, BA staff using your systems, researchers, and other outside identities that still reach ePHI or related services.
Apply appropriate identity proofing and authentication to external users so portal, partner, and guest access to ePHI is attributable and resistant to account takeover.
How this control shows up in healthcare and HIPAA-covered environments.
Attackers spray passwords against the portal. IA-8 improvements add MFA, lockout (AC-7), and breached-password checks so a reused consumer password alone cannot open labs and visit notes.
A referral office shared one portal ID across staff. Attribution and minimum necessary broke down. IA-8 requires named external provider accounts with org affiliation attributes.
A billing BA accesses your clearinghouse UI via federated SSO with MFA assertion and time-limited group membership — stronger than a standing local password emailed at onboarding.
Auditors distinguish workforce vs patient/partner authentication. Weak portal recovery and shared external IDs are frequent findings under HIPAA authentication and access control.
How this NIST control supports HIPAA Security Rule expectations.
Yes, when they authenticate to organizational systems such as patient portals or apps you operate.
Match assurance to risk. Portals with rich ePHI increasingly warrant MFA; document decisions in your risk analysis.
IA-2 = workforce identities; IA-8 = everyone else authenticating to your systems. Both need unique IDs and managed authenticators.
Related controls that commonly accompany IA-8.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.