Dental practice office monitor showing a multi-location MFA enrollment coverage dashboard with two locations flagged incomplete

Ask around whether HIPAA requires multi-factor authentication and you will get contradictory answers, most of them delivered with total confidence.

So here is the direct one. HIPAA does not name multi-factor authentication, so the MFA requirements for dental practices that actually bind you today come from your payers and your cyber carrier, contractual answers to the authentication obligation HIPAA does impose.

The regulation is years out. The contract is on your desk now.

What the Security Rule Actually Says Today

The current HIPAA Security Rule does not contain the words multi-factor or multifactor anywhere. Not in the technical safeguards at 45 CFR 164.312, not in the administrative safeguards at 164.308.

What it does require is narrower than a blanket mandate, and harder to satisfy across twenty locations than at one. Unique user identification at 164.312(a)(2)(i) is Required rather than addressable: a unique name or number tracking each user. HHS defines a user broadly, as any person or entity with authorized access, so contractors and service accounts count, not only staff, at every practice you own. The authentication standard at 164.312(d) carries no implementation specifications, so HHS names the outcome and leaves you the method.

Password management at 164.308(a)(5)(ii)(D) is Addressable, a word people misread as optional. It means you assess whether it is reasonable and appropriate for you, do it if so, and otherwise document why not and put an equivalent alternative in place where that is reasonable too. A group holding neither the assessment nor the documentation has one omission repeated at every location.

The Rule That Would Name It Is Still Proposed

Nearly everything written about a 2026 MFA mandate traces back to one document. HHS published a Notice of Proposed Rulemaking on January 6, 2025, at 90 FR 898. It would rework today’s authentication standard into a renamed one at proposed 164.312(f), with multi-factor authentication as an implementation specification under it and three exceptions, the broadest covering legacy technology under a written migration plan.

It is a proposal. The comment period closed March 7, 2025, with 4,747 comments filed. None of its MFA provisions binds anyone today.

The part almost nobody reports is where it sits now. The Unified Agenda lists it under Long-Term Actions and projects final action in July 2027, an agency estimate rather than a deadline. The proposal would take effect 60 days after a final rule, with compliance 180 days after that. If that schedule holds, compliance lands somewhere in 2028.

Anyone telling your group that HIPAA requires MFA everywhere by a 2026 deadline is reading a proposal as law. Your payers and carriers can set real dates, and several already have. What no federal rule currently does is set one, and a wrong deadline is how a multi-location rollout gets budgeted for the wrong quarter, or shelved once the panic passes.

Why the Confident Wrong Answer Keeps Showing Up

We ran the question past several AI assistants with live web search on. One answered in a bolded summary line that the final rule is in effect and MFA is now mandatory for dental practices, sourcing dental industry blogs without a government page among them.

Another, asked the same question, answered correctly and cited hhs.gov. Small sample, and the pattern was consistent: the answers tracked their sources, and the dental-specific pages in those source lists were the ones stating the proposal as settled law.

So an office manager searching this at 4pm gets a confident mandate, a CFO pricing it across nineteen locations gets a hedge, and both land in your inbox the same week. When a vendor or a consultant hands your group a compliance deadline, ask which published document it comes from. On this one, nobody can produce it.

What Already Requires MFA of You, Regardless

Here is where the honest legal answer stops being reassuring. Two sources may already make MFA mandatory for your group, depending on who you bill and who insures you, and neither waits on HHS.

The payer portals

Delta Dental’s provider page states that as of October 20, 2025, MFA is required, and calls it the new sign-in standard, required going forward to access all Delta Dental provider portals. The California Dental Association told members in September 2025 that dentists who had not enrolled by October 20 would lose portal access and have to call for help.

Read that scope carefully anyway. Delta Dental is a network of 39 independent companies whose affiliates run their own rollouts, so confirm the details for the companies you actually bill. What payer MFA does to a centralized billing team is its own subject, and where this bites hardest at scale.

Your cyber insurance carrier

For most groups the insurance application is the sharper forcing function. Carriers no longer ask whether you have MFA. They ask system by system, and we went through what dental carriers actually put on those forms in a read of the applications themselves.

Your answer is a signed representation about your environment, and depending on the policy language it can be pulled into the coverage terms. Claiming a control you cannot evidence costs you at renewal, and considerably more when a claim gets examined.

Comparison of what requires MFA of a dental group: HIPAA today does not say MFA, the proposed rule is still not final, and payer portals and cyber carriers already require it

The Question Behind the Question

Watch what happens when the question gets specific. Which systems, at which locations, for which people, enforced by what. A single office answers in a minute. A group six deals into two years starts making calls.

That gap is the finding, and rulemaking has nothing to do with it. Studying business cloud accounts flagged for suspicious activity, Microsoft researchers measured MFA as cutting the risk of compromise by 99.22 percent, and by 98.56 percent in a separate sample of accounts whose passwords had leaked. Those figures describe accounts where it is enforced. They say nothing about the eleven at your newest location that were supposed to be enrolled in March.

Coverage you cannot enumerate is not coverage. It is an assumption with good intentions behind it.

Where the Gaps Actually Sit in a Multi-Location Group

The holes are predictable, and they cluster at the seams between locations rather than inside them.

Acquired locations arrive outside your tenant. The practice you closed on last month has its own Microsoft 365 or Google tenant and its own admin accounts. Until it is migrated, your MFA policy does not reach it. Nobody decided that, which is why the gap gets measured in quarters.

Administrator accounts get exempted and stay exempted. Somebody excludes a service account during a rollout so the imaging integration keeps working. The exception outlives the reason, and nobody reviews it because nobody owns the list.

The PMS is the awkward one. A practice management system with its own local user table sits entirely outside your MFA. One that authenticates against your directory usually inherits it, though legacy sign-in paths and local fallback accounts routinely defeat that. Confirm it per system rather than assuming, and put the question to the vendor in writing.

Remote access and the backup console. These are the accounts an attacker actually wants, and both get configured per location by whoever set that location up. A group carrying three former MSPs carries three conventions here.

Banking and payroll. No ePHI, so they sit outside the HIPAA conversation and outside most compliance checklists. They are also where the wire goes.

The Objection From the Operatory Is Usually Right

When a rollout stalls at four of your locations and lands cleanly at the other fifteen, the four are usually telling you something real.

Clinical staff are gloved. An operatory workstation gets used by several people across a day, and a code prompt on a personal phone mid-procedure is a genuine workflow cost rather than resistance to change. Front desk turnover runs high, so a factor bound to a departed person’s phone becomes an access problem at that location the same week.

The CDA’s own guidance to members shows how far that pressure goes. It recommends an office phone over personal devices, and advises that an email factor be a general office mailbox the whole team can reach, because a factor tied to one employee breaks when that employee leaves.

A state association landed there because the alternative genuinely hurts at the chair, so overruling it from a corporate office solves nothing. Solving the workflow does, with device-bound authenticators, session lifetimes set for clinical use, and per-person identity behind whatever the operatory touches. Build that once and deploy it everywhere, which is the argument for standardizing IT across locations rather than renegotiating it practice by practice.

What You Should Be Able to Hand Someone

An underwriter, a buy-side team, and a regulator after an incident are all asking a version of one question, and none of them accept a policy document as the answer. Four records, and a group should be able to produce them in a day.

An enrollment report per system, per location. Pulled from the identity platform rather than assembled by asking office managers. The number that matters is how many accounts lack MFA, and their names.

The exception list, with an owner and a review date. Every excluded account, why, who approved it, and when it was last read. An empty list is fine. A list nobody has opened in a year is the finding.

An enforcement policy in writing that shows what is enforced rather than encouraged. If your MFA depends on anybody at any location remembering it, you do not have it yet.

The joiner and leaver record. When someone started and when they were enrolled. When someone left and when access was revoked, across your directory and the payer portals sitting outside it. This gets requested during IT review on an acquisition, and most groups assemble it retroactively.

None of that depends on a final rule. It is what an underwriter is asking for this quarter.

Answer It Before Someone Else Asks

Pick your largest location and the one you acquired most recently. Ask for a list of every account without MFA at each, by name, today. How long that takes, and whether both lists come out of the same system, tells you more about your security posture than any compliance checklist will.

Dental MFA Requirements FAQs

Does HIPAA require multi-factor authentication in 2026?

No. It requires unique identification for each user of a system that holds ePHI, and requires you to verify anyone seeking access is who they claim to be. MFA is a reasonable way to meet that second requirement, and the proposed rule naming it directly is not final.

Should we wait for the final rule before rolling out MFA?

No, and not because the rule is close. It is not. Wait and you are still buying MFA later, on a compressed timeline, while your carrier and your payers ask for it in the meantime. The one thing worth timing to the rulemaking is scope, since a final rule may name systems your current rollout skipped.

Is it a HIPAA violation for two people at a practice to share a login?

For systems you control that hold ePHI, yes. Asked whether the Security Rule permits a covered entity to assign the same log-on ID to multiple employees, HHS’s published guidance answers no, citing the unique user identification standard, and defines a user as any person or entity with authorized access. That applies to every ePHI system you control at every location, whatever MFA sits on top of it. Where a credential genuinely has to be shared, it belongs behind a managed password tool rather than in someone’s notes app.

Our cyber insurance application asks about MFA. What is the honest answer?

Whatever your enrollment report says, with your IT provider in the room when you answer. The trap for a group is the single application covering every location, because one signature warrants the control at all of them, including the practice that closed in March and has not been migrated. Verify at your newest location before signing, because that is where the answer usually breaks.

Does MFA on a payer portal satisfy anything for HIPAA?

It secures the payer’s system, which is the payer’s obligation, and does nothing for the systems you run. It also does not fix a shared portal login. The account gets authenticated, not the individual, so nine billers across four locations sharing one credential still resolve to a single identity in the payer’s logs.

Posted in Dental Cybersecurity

Filter By: