CYBER DENTAL 2.0
(954) 639-7049

MFA for dental practices

The cheapest control OCR keeps asking for.

Journal · Academy · C·04 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida

Short answer: Multi-factor authentication (MFA) is the cheapest high-impact control for a dental practice: it blocks most account takeovers even after a password is stolen. Enforce it first on email, remote access, administrator accounts and any cloud system holding ePHI, prefer app-based or hardware prompts over SMS, and plan for shared front-desk workstations.

At a glance

What it is Two or more proofs of identity at sign-in
Enforce first Email, remote access/VPN, admin accounts, cloud PMS and portals
Better choices Authenticator-app with number matching; hardware security keys
Weakest common choice SMS codes
Regulatory status MFA is not named in the current Security Rule; it is proposed as required in the 2025 NPRM; person-or-entity authentication is already required

What is MFA and why does it matter in a dental office?

MFA requires more than a password to sign in, typically a password plus a prompt on a phone or a hardware key. Dental offices are attractive targets because they hold identity, insurance and health data, and their accounts are often protected by a single password reused across services. When a password leaks through phishing or an old breach, MFA is the control that turns "compromised" into "attempted."

Does HIPAA require MFA?

The current HIPAA Security Rule does not name MFA. It does require procedures to verify that a person or entity seeking access to ePHI is who they claim to be (45 CFR 164.312(d)), and it requires a risk analysis, where an unprotected email account holding PHI is hard to defend. The HHS proposal to update the Security Rule (published January 2025) would require MFA explicitly, but that proposal is not final. See NPP 2026 vs the Security Rule NPRM. In practice, cyber-insurance applications and OCR enforcement expectations already treat MFA as baseline.

Where should a practice enforce MFA first?

  1. Email and Microsoft 365 / Google accounts. The most-attacked door. See Microsoft 365 for dental practices.
  2. Remote access and VPN. Anything that lets someone connect from outside.
  3. Administrator accounts on the network, firewall, cloud portals, and the MSP's own tools.
  4. Cloud PMS and patient-data portals, including payer and clearinghouse sites that support it.
  5. Password manager, since it holds everything else.

Which kinds of MFA should a practice choose?

Method Strength Note
Hardware security key (FIDO2) Strongest; phishing-resistant Best for admins and owners
Authenticator app with number matching Strong Good default for staff
Authenticator push without number matching Moderate Vulnerable to "prompt fatigue"
SMS code Weaker Better than nothing; vulnerable to SIM swap

How do you deploy MFA without slowing the front desk?

The real obstacle is shared workstations and rushed mornings, not technology. Practical approaches: give each person their own account (no shared logins); use trusted-device and conditional-access rules so a known office workstation prompts less often than an unknown location; use authenticator apps rather than carrying code lists; and have the HelpDesk ready for the first week of lost-phone resets. See What does the front desk own, and what does IT own?.

What does MFA not protect against?

MFA is not magic. Attackers can trick staff into approving a prompt, steal session tokens, or bypass it through other weaknesses. It belongs inside a layered approach with EDR, patching, backups and training.

Frequently asked questions

Is MFA required by HIPAA for dental offices?

The current Security Rule does not name MFA explicitly, but it requires verifying the identity of people accessing ePHI and a risk-based approach. MFA is proposed as mandatory in the 2025 Security Rule NPRM, which is not yet final.

Is SMS MFA good enough?

SMS is better than no MFA but weaker than authenticator apps or hardware keys because of SIM-swap and interception risks. Use stronger methods where possible, especially for administrators.

Where should a dental practice turn on MFA first?

Email, remote access, administrator accounts and any cloud system that holds ePHI.

Sources and further reading

Related in the Journal

About CyberDental

CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.

CALL TEXT