...

Ekim IT Solutions

Blog / MFA for Dental Practices: What HIPAA Now Requires
All Dental

MFA for Dental Practices: What HIPAA Now Requires

Illustration showing multi-factor authentication icons connecting to a dental office building representing HIPAA's current MFA requirements for dental practices

MFA for dental practices is no longer optional under the HIPAA Security Rule updates proposed in 2025 and moving toward implementation in 2026. HHS’s proposed updates explicitly include MFA as a required control for all authenticated access to systems housing electronic protected health information.

Ekim IT Solutions is the dental-exclusive IT provider implementing multi-factor authentication for dental practices across Maine, New England, Tampa Bay, and nationwide. For a dental practice, that means practice management software, imaging systems, email, and any cloud platform storing patient data.

Here is exactly what MFA compliance looks like for a dental practice in 2026 and what Ekim IT Solutions configures to meet it.

Why This Control Matters

The Change Healthcare breach in February 2024, which disrupted insurance claims processing for dental offices nationwide for weeks, began with a single set of compromised credentials on a remote access portal with no MFA enabled.

Not sure if MFA is enforced across every system that touches patient data? Find out in 15 minutes if we are the right fit.
Schedule a Discovery Call →

What HIPAA’s 2026 Security Rule Updates Require for MFA

HHS published proposed Security Rule updates in January 2025 that, when finalized, make MFA a required implementation specification rather than an addressable one for all authenticated access to ePHI systems. For a dental practice, this means MFA must be enabled everywhere patient data can be reached.

Practice Management Software

Every login to the PMS that stores patient charts and treatment history.

Imaging System Access

Radiograph and imaging software logins, wherever patient images are stored or accessed.

Email Accounts

Any staff email account that handles patient data or referral information.

Remote Access and VPN

Every remote connection into the practice network, without exception.

Cloud Platforms

Any dental AI suite, patient communication platform, or billing software storing PHI.

Where Dental Practices Currently Have MFA Gaps

Ekim IT Solutions identifies these as the most common MFA gaps in dental practices during onboarding assessments.

1
Email Accounts

Staff email accounts handling patient data without MFA are the most frequently found gap.

A compromised email account is the most common initial access point for ransomware targeting dental practices.

2
Remote Access

Direct RDP connections and VPN access protected by password only, with no MFA.

This is the access pattern that enabled the Change Healthcare breach and remains widespread in dental practices.

3
Insurance and Clearinghouse Portals

Many dental practices log into insurance portals and clearinghouses daily without MFA.

These portals contain patient claim data and explanation of benefits information, even when treated as low risk.

Check Your MFA Coverage

Check each control currently confirmed in place at your dental practice.

Controls confirmed in place
0 / 4

Microsoft 365 or Google Workspace MFA is enforced at the organizational level

Conditional access policies requiring MFA for all staff email accounts, not just individual enrollments.

Practice management software MFA is enabled, or compensating controls are documented

Where the PMS supports MFA natively, it is enabled and enforced. Where it does not, compensating controls are documented in the Security Risk Assessment.

MFA is enforced on all VPN connections and direct RDP is disabled

No remote session is permitted without MFA. Direct RDP replaced by MFA-protected VPN access.

MFA enrollment is verified for every cloud platform the practice uses

Including patient communication, billing, and AI suite tools that store or access patient data.

Password Security Standards Alongside MFA

MFA does not eliminate the need for strong passwords. Ekim IT Solutions implements a password policy requiring minimum 12-character passwords with complexity requirements, enforced through the practice’s identity management platform, alongside MFA across all ePHI systems.

Password reuse across dental software and non-dental accounts is one of the most common vectors for credential compromise, and a password manager deployed organization-wide reduces reuse rates significantly.

Frequently Asked Questions

Yes. HHS’s proposed 2026 Security Rule updates explicitly include MFA as a required control for all authenticated access to systems containing electronic protected health information. Dental practices should implement MFA on all ePHI systems now rather than waiting for final rule publication.
Practice management software, imaging system access, staff email accounts handling patient data, remote access and VPN connections, insurance and clearinghouse portals, and any cloud platform storing patient data including patient communication tools, billing software, and dental AI suites.
No. MFA is one required technical safeguard among several. HIPAA compliance also requires encryption, access controls, audit logging, a Security Risk Assessment, signed BAAs, and written policies. Ekim IT Solutions implements all of these as standard components for every dental practice we support.
Ekim IT Solutions audits every system that accesses patient data, enables and enforces MFA at the organizational level for email and cloud platforms, configures MFA-protected remote access, and documents each system’s MFA status in the practice’s Security Risk Assessment. This is a standard component of every managed IT engagement.
MFA is moving from best practice to HIPAA requirement in 2026. Does your practice have it configured on every system that touches patient data?

Ekim IT Solutions works exclusively with dental practices. We serve New England and New York with on-site support and dental practices nationwide with remote support. We configure and enforce MFA across your practice management software, imaging systems, email, and every cloud platform storing patient data so your practice meets the 2026 HIPAA Security Rule standard.

MFA is no longer optional under the updated HIPAA Security Rule. Find out which systems in your practice are still running without it.
Check your MFA compliance →