§164.312(d)
Person or Entity Authentication
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Verify that a person or system seeking access to ePHI is the person or entity it claims to be.
Points of focus
- Authenticate human users before granting ePHI access
- Authenticate services and external entities
- Strengthen authentication according to access risk
Implementation notes
Use phishing-resistant MFA for privileged humans, short-lived workload identities for services, and scoped partner credentials per tenant and environment; rotate or revoke credentials through tested workflows. Operationalize authenticate human users before granting ephi access in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain idp mfa and authentication-policy configuration with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a partner integration uses one permanent shared secret across environments Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample idp mfa and authentication-policy configuration with dates and named reviewers. Be ready to walk through how you detect and correct: a partner integration uses one permanent shared secret across environments
Evidence auditors typically request:
- IdP MFA and authentication-policy configuration
- Workload identity, certificate, or API credential inventory
- Authentication logs and failed-login investigations
Common gaps
- A partner integration uses one permanent shared secret across environments
- Support agents can enter an ePHI session after only password authentication
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.312(d) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.312(d)