HIPAA Password Requirements & How To Comply With Them
The article explains that while HIPAA mandates appropriate authentication to protect electronic Protected Health Information (ePHI), it does not specify exact password requirements, so healthcare organizations should follow guidance from NIST's Special Publication 800-63B and the HITRUST Alliance frameworks to implement effective password management and comply with HIPAA's Security Rule.
The Health Insurance Portability and Accountability Act (HIPAA) consists of the Security Rule and Privacy Rule, which govern the protection of Protected Health Information (PHI) and electronic Protected Health Information (ePHI). The 2009 HITECH Act created violation categories with varying degrees of penalties, overseen by the Office for Civil Rights (OCR). The increased value of ePHI records on the Dark Web and the rising rates of data breaches in the healthcare industry reinforce the importance of passwords as administrative and technical safeguards for protecting patient information.
HIPAA & Passwords
How are passwords related to HIPAA compliance?
HIPAA requires appropriate authentication methods for ePHI access and ongoing management of that access. However, HIPAA does not specify exact authentication methodologies or password complexity requirements. Organizations seeking HIPAA password compliance can refer to resources such as guidance from the National Institute of Standards and Technology (NIST) and the HITRUST Alliance.
The OCR traditionally defers to NIST for technical guidance, which offers the first step to understanding password requirements. In 2007, the HITRUST Alliance was founded to establish a cybersecurity framework focused on risks specific to the healthcare industry. Combining insights from both the NIST Cybersecurity Framework (NIST CSF) and HITRUST Cybersecurity Framework (HITRUST CSF) helps provide direction for healthcare organizations.
What are the NIST password management suggestions?
In June 2017, NIST released Special Publication 800-63B, which provides technical recommendations for choosing authenticators and authentication processes to be used at different Authenticator Assurance Levels (AALs). While not prescriptive, these suggestions establish regulatory acceptability levels.
A summary review of the AALs notes that they provide increasing levels of assurance over an organization’s authentication choices:
- AAL1: Requires linking single-factor or multifactor authentication to a specific individual.
- AAL2: Includes proof of possession and control of two different authentication protocols as well as approved cryptographic techniques.
- AAL3: The highest level of assurance, requires a hardware-based authenticator as well as one that is resistant to impersonation (one device may meet both requirements).
To achieve a basic level of authentication strength (AAL1), organizations can use any of the following:
- Memorized Secret
- Look-Up Secret
- Out-of-Band Devices
- Single-Factor One-Time Password (OTP) Device
- Multi-Factor OTP Device
- Single-Factor Cryptographic Software
- Single-Factor Cryptographic Device
- Multi-Factor Cryptographic Software
- Multi-Factor Cryptographic Device
AAL3 authentication requires a combination of authenticators from the following list:
- Multi-Factor Cryptographic Device
- Single-Factor Cryptographic Device used in conjunction with Memorized Secret
- Multi-Factor OTP device (software or hardware) used in conjunction with a Single-Factor Cryptographic Device
- Multi-Factor OTP device (hardware only) used in conjunction with a Single-Factor Cryptographic Software
- Single-Factor OTP device (hardware only) used in conjunction with a Multi-Factor Cryptographic Software Authenticator
- Single-Factor OTP device (hardware only) used in conjunction with a Single-Factor Cryptographic Software Authenticator and a Memorized Secret
The different AALs require varying complexity levels, so not every password management requirement matches every organization.
What are the HITRUST password management suggestions?
The HITRUST Alliance released version 9 of the CSF after the release of the NIST Special Publication, establishing 19 controls to align with SP800-63B. Many covered entities choose to comply with the HITRUST CSF since it incorporates ISO 27000, COBIT, HIPAA, NIST, PCI DSS, FTC Red Flags, HITECH Act, and several other standards, including state requirements.
The HITRUST CSF provides sector-specific controls targeting different healthcare provider needs. For example, physicians can use tokens, smartcards, or biometrics as authentication methods instead of, not in addition to, passwords. Tapping a smartcard rather than typing in a password is intended to speed the authentication process, allowing the physician to more rapidly provide care.
What are the HITRUST password complexity suggestions?
HITRUST allows organizations to choose a level of compliance. When reviewing the password management requirements, the different compliance requirements between the levels give insight into how HITRUST allocates responsibility based on risk.
-
Level 1 organizations must require passwords that:
- Are not displayed when entered
- Are changed in the event of a possible system or password compromise
- Allow user identity verification before performing password resets
-
Level 2 organizations must incorporate all Level 1 requirements and also:
- Protect passwords from unauthorized disclosure and modification when stored and transmitted
- Prevent passwords from being included in any automated log-on process (e.g., stored in a macro or function key)
- Encrypt passwords during transmission and storage on all system components
- Create temporary passwords that are unique to an individual and not guessable
- Require users to sign a statement attesting to the confidentiality of personal and group passwords
HITRUST’s standard and framework aggregation incorporates several suggestions for creating a strong password. Password complexity aligns with CMS implementation, FEDRAMP, HIX, and PCI DSS. For users, FEDRAMP requires a minimum 12-character password length, while HIX has a shorter requirement of 8 characters. The CMS, FEDRAMP, and HIX implementations all require a password to include one capital letter, one lowercase letter, one number, and one special character.
Organizations seeking HIPAA compliance should create a password policy clearly defining a strong user password and engage in security awareness training for all employees.
How ZenGRC Enables HIPAA Compliance
ZenGRC eases the compliance burden by providing organizations with seed content for mapping their controls across a variety of standards and frameworks. This speeds the onboarding process and also enables gap analysis.
Healthcare providers can choose from HITRUST, COBIT, COSO, ISO, PCI DSS, and NIST frameworks to ensure proper IT HIPAA compliance. Business partners seeking to become HIPAA compliant as they scale can quickly view their current compliance using the gap analysis tool and determine how much additional work they need to do.