How to Run a Security Risk Assessment for Clinics Adopting Passwordless Passkeys for EHR Login

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Run a Security Risk Assessment for Clinics Adopting Passwordless Passkeys for EHR Login

Kevin Henry

Risk Management

August 28, 2026

7 minutes read
Share this article
How to Run a Security Risk Assessment for Clinics Adopting Passwordless Passkeys for EHR Login

Adopting passwordless passkeys can strengthen EHR login while reducing password fatigue and phishing risk. A focused security risk assessment helps you validate benefits, expose gaps, and document decisions that support HIPAA compliance and safe clinical operations.

Security Risk Assessment Purpose

The purpose is to evaluate how passkeys affect confidentiality, integrity, and availability of electronic health records, and to determine whether risks are acceptable after controls are applied. You aim to quantify passkey compromise risk and confirm that safeguards preserve patient data confidentiality and workflow efficiency.

  • Define scope: EHR sign-in, identity provider (IdP), authenticator types (platform vs. roaming), recovery flows, and administrative access.
  • Set objectives: strengthen EHR access control, meet HIPAA compliance and HITECH regulations, and reduce account takeover and phishing exposure.
  • Identify deliverables: system diagram, data-flow map, risk register, controls mapping, and a plan of action and milestones (POA&M).
  • Name stakeholders: clinical leadership, privacy/compliance, IT/security, help desk, EHR and IdP vendors, and third-party business associates.

Initial Steps for EHR Security

Establish scope and assets

  • Inventory EHR applications, IdP, devices (managed and BYOD), authenticators, and admin consoles involved in login and session management.
  • Map data flows from authentication through session creation, including token issuance, SSO, and audit logging.

Baseline controls and posture

  • Verify device security: MDM enrollment, screen lock, disk encryption, patch levels, and endpoint protection on clinical workstations and mobile devices.
  • Review EHR access control design: unique user IDs, role-based access (RBAC), “break-glass” policies, and automatic logoff in shared clinical areas.

Define risk methodology

  • Use a consistent scale for likelihood and impact; record assumptions and evidence for each rating.
  • Set thresholds for remediation versus risk acceptance, aligned with clinical safety and regulatory expectations.

Design recovery from the start

  • Document a multi-factor authentication fallback that avoids weak factors (e.g., SMS) and limits exposure during recovery.
  • Plan identity-proofing steps for enrollment and recovery to prevent social engineering at the service desk.

Threat Identification in Passkey Adoption

Key threat scenarios

  • Device theft with saved platform passkeys leading to unauthorized EHR access if screen locks are weak or absent.
  • Abuse of recovery: attacker convinces help desk to reset factors, bypassing passkey protections.
  • Configuration errors: mis-scoped IdP applications, permissive redirect URIs, or incorrect relying party IDs enabling session hijack or token misuse.
  • Supply-chain compromise of IdP/EHR vendor or authenticator firmware resulting in credential misuse at scale.
  • Fallback downgrade: attackers force users into legacy methods if insecure recovery remains enabled.
  • Insider misuse: legitimate users access more PHI than needed due to excessive privileges or shared accounts.
  • Availability threats: large-scale lockouts or authenticator sync outages that delay clinical care.

For each threat, document entry points (enrollment, recovery, authentication, administration), attacker goals, and controls that specifically mitigate passkey compromise risk.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Vulnerability Analysis of Passkey Systems

People and process weaknesses

  • Inadequate identity proofing for remote onboarding or recovery, enabling impersonation.
  • Unclear break-glass rules, causing overuse of emergency access with limited oversight.
  • Service desk scripts that disclose too much information or allow resets without strong verification.

Technology weaknesses

  • Unmanaged devices permitted for EHR login without posture checks or attestation policies.
  • Passkeys allowed without requiring device unlock (biometric/PIN), weakening user verification.
  • Overly long sessions, insufficient inactivity timeouts, or missing token binding increasing replay risk.
  • Fallback methods that are not phishing-resistant and remain widely enabled.
  • Insufficient logging of WebAuthn events, authenticator AAGUIDs, and admin changes, hindering investigations.

Validation activities

  • Hands-on tests: enrollment, recovery, lost-device revocation, and admin impersonation attempts.
  • Configuration review: IdP/OIDC settings, allowed authenticators, attestation and key protection policies.
  • Tabletop exercises: simulate help-desk social engineering and mass device loss.

Impact Assessment on Patient Data

Rate consequences across the CIA triad with emphasis on patient data confidentiality and clinical safety. Consider record volume reachable per account, sensitivity of accessible modules (e.g., notes, imaging, labs), and downstream systems like e-prescribing.

  • Confidentiality: unauthorized PHI exposure leading to regulatory penalties, patient harm, or reputational damage.
  • Integrity: altered medication orders or documentation affecting clinical decisions.
  • Availability: authentication outages delaying care, increasing length of stay, or triggering downtime procedures.

Quantify impact using measurable proxies such as potential records affected, critical function downtime, cost of breach response, and time to revoke compromised authenticators.

Mitigation Strategies for Passwordless Access

Strengthen authenticators and devices

  • Require device unlock for all passkey use and enforce MDM controls on clinical endpoints.
  • Prefer phishing-resistant, hardware-protected authenticators; restrict to trusted AAGUIDs via policy.
  • For admins and high-risk roles, mandate separate hardware security keys with step-up authentication.

Design secure enrollment and recovery

  • Use robust identity proofing (in-person or high-assurance remote verification) with dual authorization for resets.
  • Issue limited-lifetime recovery codes; monitor and alert on recovery events and unusual locations/devices.
  • Document rapid revocation workflows and remote wipe for lost or retired devices.

Constrain access and sessions

  • Harden EHR access control with least privilege, contextual policies (location, device posture), and short session lifetimes.
  • Enable step-up prompts for sensitive actions such as exporting large PHI sets or approving high-risk orders.

Operational readiness

  • Integrate logs into your SIEM, correlating WebAuthn events, device posture, and PHI access patterns.
  • Train clinicians and service desk staff to recognize social engineering and to use break-glass appropriately.
  • Maintain tested incident response playbooks for suspected account compromise and widespread authenticator failures.

Compliance Checkpoints for Healthcare Regulations

  • HIPAA compliance: document risk analysis and risk management decisions, workforce training, access control, audit controls, integrity, authentication, and transmission security.
  • HITECH regulations: ensure breach detection and notification processes align with statutory requirements and that encryption and strong authentication are applied to reduce exposure.
  • Business associate oversight: update BAAs to reflect authentication data handling, logging, and incident responsibilities.
  • Auditability: preserve detailed logs of authenticator enrollment, recovery, admin actions, and PHI access for investigations.
  • Framework alignment: map controls to recognized cybersecurity frameworks healthcare to guide maturity improvements and executive reporting.

Monitoring and Reporting Procedures

What to monitor

  • Enrollment and recovery anomalies: spikes by site, user role, or time; repeated failed verifications.
  • Authenticator inventory: AAGUID distribution, unmanaged devices, and stale or orphaned credentials.
  • Fallback usage rate: elevated reliance on multi-factor authentication fallback signals misconfiguration or abuse.
  • Access patterns: unusual PHI queries, bulk exports, or access from atypical locations or device postures.
  • Control health: MDM compliance, patch levels, EDR alerts, and log ingestion completeness.

Reporting and review cadence

  • Weekly: operations dashboard for enrollment, recovery, and high-risk events; ticket aging for revocations.
  • Monthly: control effectiveness review, exceptions, and POA&M progress for leadership and compliance.
  • Quarterly: access recertification, role reviews, disaster recovery tests, and tabletop exercises.
  • Event-driven: incident reports with timelines, root cause, affected PHI scope, and corrective actions.

Summary

By scoping systems, identifying threats, validating vulnerabilities, and implementing layered controls, you can deploy passkeys that enhance security and usability. Ongoing monitoring, disciplined recovery, and clear documentation align the program with HIPAA compliance, HITECH regulations, and clinical safety goals.

FAQs.

What are the main risks of using passwordless passkeys for EHR login?

Primary risks include device theft with weak screen locks, social engineering of recovery workflows, configuration errors in the IdP or EHR, insecure fallback methods, and insider misuse of broad privileges. Each can elevate passkey compromise risk and must be offset with device controls, strong recovery, tight scopes, and continuous monitoring.

How can clinics ensure HIPAA compliance with passkey systems?

Perform a documented risk analysis, implement appropriate administrative, physical, and technical safeguards, and maintain auditable logs of enrollment, recovery, and PHI access. Enforce least-privilege EHR access control, train the workforce, manage business associates, and review controls regularly to evidence compliance.

What mitigation strategies are effective for passkey security?

Require device unlock for all authentications, restrict to trusted authenticators, harden enrollment and recovery with strong identity proofing, minimize and monitor multi-factor authentication fallback, enforce short sessions with step-up for sensitive actions, and integrate detailed logging with automated alerts and rapid revocation.

How often should security risk assessments be updated?

Update the assessment at least annually and whenever you introduce major changes—such as new authenticators, IdP/EHR upgrades, or policy shifts—or after any security incident. Treat it as a living document that tracks risks, decisions, and POA&M status over time.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles