---
title: Healthcare Multi-factor Authentication | Zero Trust Solutions
description: NHS has now mandated to protect patient data and deliver patient care services via MFA controls.
---

[![Logo](https://ztsolutions.io/hubfs/2022%20Assets/ZTS%20Logo.png)](https://ztsolutions.io/?hsLang=en)

- [Know. Consulting](https://ztsolutions.io/services/know?hsLang=en)
  
  [Know: Your start line](https://ztsolutions.io/heathcare-mfa#knowstartLine) [Know: What to protect](https://ztsolutions.io/heathcare-mfa#knowwhatProtect) [Know: Your next steps](https://ztsolutions.io/heathcare-mfa#knowYourNextSteps)
  
    - [Know: Your Threat Landscape](https://ztsolutions.io/know-your-threat-landscape?hsLang=en)
    - [Know: Your Assets](https://ztsolutions.io/know-consulting/know-your-assets?hsLang=en)
    - [Cyber Security Awareness Tranining](https://ztsolutions.io/know-cyber-security-awareness-training?hsLang=en)
  
  
    - [Know: Cyber Assessments](https://ztsolutions.io/know-cyber-assessments?hsLang=en)
  
  
    - [ZT Strategy Workshops](https://ztsolutions.io/know-zerotrust-strategy-workshop?hsLang=en)
    - [ZT Tactical Workshops](https://ztsolutions.io/know-zerotrust-tactical-workshop?hsLang=en)
    - [ZT Practical Workshops](https://ztsolutions.io/know-zerotrust-practical-workshop?hsLang=en)
- [Empower. Resourcing](https://ztsolutions.io/services/empower?hsLang=en)
  
    - [MAIE - Microsegmentation AI Engineer](https://maie.ztsolutions.io)
    - [Virtual CISO](https://ztsolutions.io/empower-virtual-ciso?hsLang=en)
    - [Programme and Project Management](https://ztsolutions.io/empower-programme-and-project-management?hsLang=en)
    - [Cloud Security Specialists](https://ztsolutions.io/empower-cloud-security-specialists?hsLang=en)
    - [Cyber Security Specialists](https://ztsolutions.io/empower-cyber-security-specialists?hsLang=en)
    - [Identity Access](https://ztsolutions.io/empower-identity-access?hsLang=en)
    - [Microsegmentation Engineering](https://ztsolutions.io/empower-microsegmentation-engineering?hsLang=en)
- [Solve. Solutions](https://ztsolutions.io/services/solve?hsLang=en)
  
    - [MAIE - Microsegmentation AI Engineer](https://maie.ztsolutions.io)
    - [Micro-segmentation](https://ztsolutions.io/solve-micro-segmentation?hsLang=en)
    - [ZT Network Access (ZTNA / SDP)](https://ztsolutions.io/solve-zero-trust-network-access?hsLang=en)
    - [Multi-factor Authentication](https://ztsolutions.io/solve-multi-factor-authentication?hsLang=en)
    - [Anti-ransomware](https://ztsolutions.io/solve-anti-ransomware?hsLang=en)
    - [Secure Backups](https://ztsolutions.io/solve-secure-backups?hsLang=en)
    - [Asset Compliance](https://ztsolutions.io/solve-asset-compliance?hsLang=en)
    - [Risk Discovery](https://ztsolutions.io/solve-risk-discovery?hsLang=en)
- [About](https://ztsolutions.io/about-us?hsLang=en)
- [Careers](https://ztsolutions.io/careers?hsLang=en)
- [About](https://ztsolutions.io/about-us?hsLang=en)
  
    - [About Us](https://ztsolutions.io/about-us?hsLang=en)
    - [Careers](https://ztsolutions.io/careers?hsLang=en)
- [Insights](https://ztsolutions.io/insights?hsLang=en)
  
    - [Insights](https://ztsolutions.io/insights/?hsLang=en)
    - [Webinars](https://ztsolutions.io/insights/tag/webinar?hsLang=en)
    - [Events](https://ztsolutions.io/insights/tag/events?hsLang=en)
- [Get in touch](https://ztsolutions.io/contact-us?hsLang=en)

[![Logo](https://ztsolutions.io/hubfs/2022%20Assets/ZTS%20Logo.png)](https://ztsolutions.io/?hsLang=en)

- [Know. Consulting](https://ztsolutions.io/services/know?hsLang=en)
  
    - Know: Your start line
    - [Your Threat Landscape](https://ztsolutions.io/know-your-threat-landscape?hsLang=en)
    - [Your Assets](https://ztsolutions.io/know-consulting/know-your-assets?hsLang=en)
    - Know: What to protect
    - [Cyber Assessments](https://ztsolutions.io/know-cyber-assessments?hsLang=en)
    - Know: Your next steps
    - [ZT Strategy Workshops](https://ztsolutions.io/know-zerotrust-strategy-workshop?hsLang=en)
    - [ZT Tactical Workshops](https://ztsolutions.io/know-zerotrust-tactical-workshop?hsLang=en)
    - [ZT Practical Workshops](https://ztsolutions.io/know-zerotrust-practical-workshop?hsLang=en)
    - [Cyber Security Awareness Tranining](https://ztsolutions.io/know-cyber-security-awareness-training?hsLang=en)
- [Empower. Resourcing](https://ztsolutions.io/services/empower?hsLang=en)
  
    - [MAIE: Microsegmentation AI Engineer](https://maie.ztsolutions.io/)
    - [Virtual CISO](https://ztsolutions.io/empower-virtual-ciso?hsLang=en)
    - [Programme and Project Management](https://ztsolutions.io/empower-programme-and-project-management?hsLang=en)
    - [Cloud Security Specialists](https://ztsolutions.io/empower-cloud-security-specialists?hsLang=en)
    - [Cyber Security Specialists](https://ztsolutions.io/empower-cyber-security-specialists?hsLang=en)
    - [Identity Access](https://ztsolutions.io/empower-identity-access?hsLang=en)
    - [Microsegmentation Engineering](https://ztsolutions.io/empower-microsegmentation-engineering?hsLang=en)
- [Solve. Solutions](https://ztsolutions.io/services/solve?hsLang=en)
  
    - [MAIE: Microsegmentation AI Engineer](https://maie.ztsolutions.io/)
    - [Multi-factor Authentication](https://ztsolutions.io/solve-multi-factor-authentication?hsLang=en)
    - [Anti-ransomware](https://ztsolutions.io/solve-anti-ransomware?hsLang=en)
    - [Secure Backups](https://ztsolutions.io/solve-secure-backups?hsLang=en)
    - [Asset Compliance](https://ztsolutions.io/solve-asset-compliance?hsLang=en)
    - [Risk Discovery](https://ztsolutions.io/solve-risk-discovery?hsLang=en)
    - [Micro-segmentation](https://ztsolutions.io/solve-micro-segmentation?hsLang=en)
- [About](https://ztsolutions.io/about-us?hsLang=en)
- [Careers](https://ztsolutions.io/careers?hsLang=en)
- [About](https://ztsolutions.io/about-us?hsLang=en)
  
    - [Careers](https://ztsolutions.io/careers?hsLang=en)
- [Insights](https://ztsolutions.io/insights?hsLang=en)
- [Webinars](https://ztsolutions.io/insights/tag/webinar?hsLang=en)
- [Events](https://ztsolutions.io/insights/tag/events?hsLang=en)
- [Get in touch](https://ztsolutions.io/contact-us?hsLang=en)

![Mask Group 89-1](https://ztsolutions.io/hs-fs/hubfs/Mask%20Group%2089-1.png?width=1440&name=Mask%20Group%2089-1.png "Mask Group 89-1")

# Solve: Healthcare Multi-factor authentication (MFA)

NHS has now **mandated** to protect patient data and deliver patient care services **via MFA controls.**  

With the mandate that MFA is required to protect not just your email, but your online Applications, what are the options for your sector? 

 

[Contact us](mailto:hello@ztsolutions.io)

**What should you do?** 

If you haven’t already, now is a good time to: 

1. **Understand** the NHS mandate / policy - you can find it [here](https://digital.nhs.uk/cyber-and-data-security/guidance-and-assurance/multi-factor-authentication-mfa-policy?key=cici4E7F7HvH3RYbRs3I8yNeKW84iV7rZ6cmJmCpeik4iHKlXWksPCu2AVqp1Q2G)
2. **Check** if you are prepared with the **health check below**.  
3. **Analyse** the best MFA options for your needs. 

![MFA Mandate](https://ztsolutions.io/hs-fs/hubfs/MFA%20Mandate.png?width=940&height=348&name=MFA%20Mandate.png)  
For your Service Users, Carers, Staff, and your wider workforce:  

1. Have you discovered and updated your data access flows?   
     1. 1. E.g. where does your admission data come from and go to? 
            2. Do you have demographic data flowing from a trust to a hospital? 
            3. Are they included in your Combined Information Assets and Flows Register (IAFR)? 
2. Is your organisation’s information asset register (IAR) up to date? 
3. For your IAFRs, have you secured the data collection process itself? 
4. Do you have an Identity Provider for authentication? 
5. Have you configured Single Sign On (SSO) where possible?
6. Already have multiple MFA, define your strategy and reduce costs
   
   [![Get in touch, we can walk you through the process](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/24946781/f6ce0792-0cfd-4a72-9d77-6772e80ae2ec.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/24946781/f6ce0792-0cfd-4a72-9d77-6772e80ae2ec)
   
    

MFA options vary in cost and even security levels themselves. This can be very confusing to your staff and even partners. 

 

MFA Variations at the NHS include, Authenticator apps, SMS, Hardware tokens, Security Keys, Biometrics, Cards, however on most occasions a single option won’t be enough or practical for your part of the NHS. 

 

At Zero Trust Solutions we assess and offer independent advise on the most cost effective and best options for you, whether it’s Staff who do not want to use their personal device for work or for areas that do not allow mobile devices, shared workstations, multiple devices etc 

 

Talk to us on how we can help save you money, plus advise you on the best options to enable MFA and your Zero Trust roadmap

 

## How to protect your accounts

One of the greatest threats against your personal security is an attacker taking control of an online account. With it, a threat actor can do all sorts of nefarious deeds in your name, and if they get control of your email account, they can use password recovery features to control even more of your accounts. Fortunately, multi-factor authentication (MFA) can protect against account takeovers. 

 

[Learn more](https://ztsolutions.io/insights/what-is-multi-factor-authentication-mfa-and-how-is-it-set-up?hsLang=en)

![Mask Group 100](https://ztsolutions.io/hubfs/Mask%20Group%20100.png "Mask Group 100")

![Group 24093](https://ztsolutions.io/hs-fs/hubfs/Group%2024093.png?width=345&name=Group%2024093.png "Group 24093")

## What is multi-factor authentication (MFA)? 

You are probably likely familiar with the username and password authentication method. However, passwords have several problems. Humans aren’t the best at remembering passwords and are even worse at picking unique, complex passwords  that can stand up to attacks. What’s more, people tend to reuse passwords, meaning that if one account is compromised, all the other accounts with the same password are also at risk. 

Multi-factor authentication, sometimes known as two-factor authentication or 2FA, seeks to change that by using more than one authentication factor. That doesn’t mean a second password, but at least any two from a list of three possible factors: 

- Something you know
- Something you have
- Something you are

[Find out more](https://ztsolutions.io/insights/what-is-multi-factor-authentication-mfa-and-how-is-it-set-up?hsLang=en)

Multi-factor authentication (MFA) is widely recognised as one of the most effective ways to protect data and accounts from unauthorised access. This policy will ensure that MFA is used on digital systems throughout the health sector, with particular requirements on accounts that are remotely accessible or have privileged access to systems. 

Both the policy and guidance are aimed at senior IT leads, cyber security leads or any other appropriate person in organisations.

The policy has been adopted by the Department of Health and Social Care as guidance under s3(3)(b) of the Network and Information Systems (NIS) Regulations 2018. Organisations that are designated under the Regulations as operators of essential services for the health sector have a statutory obligation under s10(4) to have regard to such guidance.   
   
This policy currently applies to: 

- NHS trusts and foundation trusts
- integrated care boards
- arm’s length bodies of the Department of Health and Social Care
- commissioning support units in NHS England
- operators of essential services for the health sector in England as designated under the NIS Regulations 

The accompanying guidance provides further details on how cyber, IT or the appropriate leads within your organisation can apply MFA within their own organisation and includes exemptions and scenarios to support implementation.

 

![NHS Logo](https://ztsolutions.io/hs-fs/hubfs/NHS%20Logo.png?width=290&height=290&name=NHS%20Logo.png)

Something you [know](https://ztsolutions.io/services/know?hsLang=en) is typically a password. It lives in your head and is ideally known only to you. Something you have could be a USB security key or an authenticator app on your phone. It’s something that isn’t easy for a stranger to access or obtain. Finally, something you are is a physical characteristic that can be read with a [biometric](https://ztsolutions.io/insights/why-you-should-be-using-biometric-multi-factor-authentication?hsLang=en) scan – such as a fingerprint scan or facial recognition. 

Because it’s extremely unlikely an attacker will have more than one of these forms of authentication, MFA makes it much harder for threat actors to take over accounts. For example, when [Google required their employees to use hardware MFA keys](https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/), account takeovers effectively vanished. 

MFA has become a mainstay of the security industry over the past decade. The first generation of MFA commonly used a one-time authentication code sent over SMS. So, if you’ve ever had to input a one-time password (typically a series of six or eight numbers) then you’ve used MFA without knowing it. 

![Phase-6-assets-multifactor-authentication-2](https://ztsolutions.io/hubfs/Phase-6-assets-multifactor-authentication-2.svg "Phase-6-assets-multifactor-authentication-2")

### The five most common multi-factor authentication methods

![np_password_4954169_000000](https://ztsolutions.io/hubfs/np_password_4954169_000000.svg)

SMS-based one-time passwords (OTPs): where you log in with your username and password, and you're sent a 6 to 8-digit one-time password (OTP) that's different every time.

![np_usb_1046073_000000](https://ztsolutions.io/hubfs/np_usb_1046073_000000.svg)

Hardware one-time password (OTP) tokens: hardware-based devices are usually in the form of a dongle on your keyring, smart card, or USB key.  These devices generate one-time codes based on a cryptographic key stored inside the device.

![np_mobilephone_5116418_000000](https://ztsolutions.io/hubfs/np_mobilephone_5116418_000000.svg)

One-time passcode mobile apps: an app you install from the app store on your mobile that you register as an MFA one-time password authenticator for a particular online account.

![np_phone-security_2411093_000000](https://ztsolutions.io/hubfs/np_phone-security_2411093_000000.svg)

Soft token software development kits (SDKs): software that can be embedded into a mobile app.  The app then utilises cryptographic operations to authenticate the user and device using the mobile operating system's biometric authentication capabilities.

![Healthcare MFA - Facial Detection](https://ztsolutions.io/hubfs/np_search_4759336_000000.svg)

Face Detection Technology : Proprietary facial biometrics solution to verify and uniquely identify the authenticating user. Our facial biometrics pipeline is based on many years of research and includes liveness check, face detection, and face recognition.

[Check out our blog post](https://ztsolutions.io/insights/what-is-multi-factor-authentication-mfa-and-how-is-it-set-up?hsLang=en)

### Choosing the best multi-factor authentication for your Healthcare organisation

When shopping for a USB security key, you should look for FIDO U2F certification, which means it should work with most basic security key applications.   

[FIDO2/Web Authentication (WebAuthn)](https://fidoalliance.org/certification/) is the future-proof next-generation standard that can support additional types of authentication. If you want to use a device for [biometric MFA](https://ztsolutions.io/insights/why-you-should-be-using-biometric-multi-factor-authentication?hsLang=en) or passwordless login, you’ll need FIDO2/WebAuthn. 

![Group 25161](https://ztsolutions.io/hubfs/Group%2025161.svg "Group 25161")

### Contact us by filling out the form below

## Why ZTS?

 

#### We are a Zero Trust consultancy.

Our Zero Trust Solutions consultants can help you choose the right multi-factor authentication type for your business.  We factor in many concerns, including:

- How the MFA will help with your passwordless and your [Zero Trust](https://ztsolutions.io/insights/what-is-zero-trust-architecture-and-what-are-the-benefits?hsLang=en) journey
- Accessibility concerns across your organisation
- An end-to-end lifecycle process to account for loss, upgrades and stolen devices.

[Contact us directly](https://ztsolutions.io/contact-us?hsLang=en)

- [Home](https://ztsolutions.io/?hsLang=en)
- [About Us](https://ztsolutions.io/about-us?hsLang=en)
- [Know. Consulting](https://ztsolutions.io/services/know?hsLang=en)
- [Empower. Resourcing](https://ztsolutions.io/services/empower?hsLang=en)
- [Solve. Solutions](https://ztsolutions.io/services/solve?hsLang=en)
- [Insights](https://ztsolutions.io/insights?hsLang=en)

[hello@ztsolutions.io](mailto:hello@ztsolutions.io)

- <https://www.linkedin.com/company/zero-trust-security-solutions>
- <https://twitter.com/ztsolutions_io>
- Stay Connected

**United Kingdom**

[+44 207 123 9428](tel:+442071239428)

**United States**

[+1 628 222 4246](tel:+1%20628%20222%204246)

**UAE/Dubai**

[+971 xxx xxx xxx](tel:+971%20XXX%20XXX%20XXX)

![ZTS Logo](https://ztsolutions.io/hubfs/2022%20Assets/ZTS%20Logo.png)

- [Privacy Policy](https://ztsolutions.io/privacy?hsLang=en)
- [Terms & Conditions](https://ztsolutions.io/terms-conditions?hsLang=en)

 Copyright © 2026 ZeroTrust Security Solutions LTD ("ZTS") - All Rights Reserved.

 Made by: [Heyoo](https://heyoo.agency)