Menu Close

MFA for Healthcare: Passwords, Medical Practices, and Patient Data Risk

It's not your software that's putting patients at risk. It's your passwords.

Most healthcare data is not lost to anything sophisticated. It is lost because a password ended up somewhere it shouldn’t have. 

That is the uncomfortable, ordinary truth behind most breaches in this sector. It usually isn’t a targeted attack or anything technically clever. It’s a login sitting somewhere it shouldn’t, waiting for the wrong person to find it. 

Why healthcare holds so much risk in one place 

Healthcare concentrates an unusual amount of sensitive information in one place, and this is true no matter what practice or clinic you are running. Imaging, diagnostic results, medication records and referral histories all sit alongside bookings and billing, often behind the same login that opens everything else. 

One password can reach a patient’s entire medical history plus their financial details. That is a lot of weight resting on something a person typed once, then reused, wrote down, or shared with a colleague to save time during a busy clinic day. 

The OAIC’s latest figures still list health as Australia’s most breached sector, sitting at 18 percent of all reported breaches (OAIC, 2025). That figure has stayed stubbornly high for years now, across GP practices and specialist clinics alike.  

Where the actual gap sits 

Here is the part that tends to surprise practice managers and clinic owners when it comes up in conversation. The gap usually is not in the clinical software itself. Third party systems all have solid security foundations built in. 

The gap sits around the edges, in things like: 

  • A login shared between two or three staff members because setting up separate accounts felt like a hassle at the time 
  • An old staff account nobody remembered to close after someone left  
  • A password jotted near reception because someone forgot it mid shift  
  • A login reused across the clinical system, email and the billing portal, so one leak opens three doors instead of one 

None of these require a skilled attacker. They just require the password to end up somewhere it shouldn’t, which happens far more easily than most people expect. 

What multi-factor authentication changes 

Multi-factor authentication does not solve everything. It will not stop every kind of attack, and anyone who tells you it does is overselling it. 

What it does is close the easiest door. A password on its own stops being enough to get in. Add a second step, such as: 

  • A code sent to a phone or email  
  • An approval through an authenticator app
  • and the person trying to log in with a stolen password hits a wall the password alone cannot get past. 

For a practice manager already juggling compliance obligations on top of a full clinical calendar, that is not a small thing. It is one control that meaningfully reduces the risk of the exact scenario that keeps a practice owner up at night, a breach that reaches patients and referral partners before the practice even knows it happened. 

Why some practices stall anyway 

The setup itself is rarely the hard part. Most clinics that stall on MFA get stuck somewhere else, such as: 

  • Getting every staff member across a new step in their morning login 
  • Deciding which systems need it first and which can wait a fortnight 
  • Working out who owns the decision when a practice has several doctors or partners logged in under their own names 
  • Finding a window to roll it out without disrupting a full clinic day 

If your practice has looked at MFA and paused, you are not behind. You are in good company. It is worth working out what got in the way though, because the fix is usually smaller than it looks from the outside.