Security — Is MFA required under HIPAA?

HIPAA does not explicitly mandate MFA by name, but it requires access controls and authentication measures that reasonably protect PHI. MFA is the industry-accepted standard for meeting that requirement and is what we enforce on all systems handling patient data.