
- September 25, 2018 edition
- Volume 95
- Issue 18
4 reasons two-factor authentication isn’t a silver bullet
Two methods are better than one, but nothing is foolproof to stop eager hackers.
Hacking remains a constant threat, but with each security lapse, we learn something important about the shortcomings of our current data protection methods. In October 2017, for example, hackers exposed the personally identifiable information (PII) of 
This isn’t uncommon: 
To protect patients’ health records, many organizations have turned to two-factor authentication to maintain data security. The goal is to go beyond passwords and add something unique to the user-making it harder for thieves to spoof.
To meet 
However, two-factor authentication isn’t a silver bullet against all security breaches, and even though two methods are better than one, neither is truly foolproof. When implementing two-factor authentication, be wary of these shortcomings:
1. Text codes are convenient but susceptible.
SMS text codes are one of the most popular authentication methods because of their convenience. Our phones have become an extension of ourselves, and it wouldn’t take long to realize it was missing. But if it doesget stolen, cybercriminals are instantly closer to infiltrating your healthcare organization. In some cases, thieves don’t even need the physical phone. There have been reports of hackers 
The mobile market doesn’t have much incentive to increase security, either. Two major networks dominate the market, and the industry has remained one of the 
One solution is to use a time-sensitive code that expires after being sent, shortening the window of time thieves have to hijack the SMS service. You can also add an additional layer of security with 
2. User fatigue is a real problem.
Two-factor authentication promises an additional layer of security, but compliance can be burdensome. Perhaps that’s why Google recently revealed that 
Hospital staff members are constantly pressed for time, and the idea of taking extra steps, even if they’re for a good reason, won’t sound appealing. As a result, they’ll be keen on finding ways to get around their own two-factor authentication to save time-making mistakes or ignoring some of the processes altogether. This can cause technical errors and bog down the tech help desk, giving hackers a weak link to exploit.
To reduce fatigue, personalize two-factor authentication with adaptive risk assessments that analyze each user’s IP address, location, device, and credential behavior every time he or she signs in. The second authentication will only be triggered if an anomaly indicates a potential risk rather than every time an employee signs in.
3. Trusted devices create liability.
When you label devices as “trusted” within your network, they only require two-factor authentication periodically. If access to the trusted device is compromised, two-factor authentication loses its value. The device doesn’t need to be stolen to be comprised, either. Organizations often forget to update their trusted devices list when employees leave or when devices are lost. As long as those devices remain trusted, they’re a huge liability.
In addition to routinely updating your list of trusted devices, you can encrypt and password-protect them for added security. You might even consider putting a time limit on how long devices are considered trusted. Limiting who can view sensitive information by implementing role-based access to patient records and protected health information is another way to protect data.
4. You’re never fully protected.
Once you see improvement in user engagement and lower security risks, it’s easy to become overconfident in your security measures. Remember that two-factor authentication is not people-proof and security threats are constantly evolving.
An excess of confidence leaves your employees more likely to take the bait of a crafty scheme, especially now that phishing attacks are sneakier than ever. For example, a hacker recently 
The trick worked because the only difference between LinkedIn and the email’s origin was an L in place of an I in the URL. Details like this are easy to miss, so make sure every employee carefully examines the origin of any unsolicited or unexpected email-even if it seems authentic.
Two-factor authentication is a significant step toward protecting your organization, but it doesn’t change the fact that healthcare remains one of the most vulnerable industries. Follow the strictest precautions possible, even after implementing two-factor authentication, and utilize additional features to help build up the security it already provides.
Articles in this issue
about 7 years ago
Your voice: Stop Medicare 'home invasions'about 7 years ago
Cryptocurrency: good investment or financial disaster?about 7 years ago
The quest to find affordable insulin for patientsabout 7 years ago
How to sell your medical practiceabout 7 years ago
What association health plans mean for physicians and their patientsabout 7 years ago
Coding case study: hypothyroidism and radiculopathyabout 7 years ago
Malpractice guideabout 7 years ago
As physicians, we often see what we want to seeabout 7 years ago
Reducing physician burnout starts with increasing advocacyabout 7 years ago
Direct primary care: three key consequences of dropping payersNewsletter
Stay informed and empowered with Medical Economics enewsletter, delivering expert insights, financial strategies, practice management tips and technology trends — tailored for today’s physicians.



















