Modern Identity Defense for Healthcare Series—Passkeys in Practice
← Back to All Podcasts Modern Identity Defense for Healthcare Series—Passkeys in Practice In this episode, Eric Englebretson, Besler Holdings’ VP of Information Technology, provides us with a glimpse into our next Hospital Finance Academy Webinar, the second in the Modern Identity Defense for Healthcare series, Passkeys in Practice , live on Wednesday, September 16, at 1 PM ET. Highlights of this episode include: What we can expect in this second installment in this series? Why passkeys specifically? How MFA isn’t solving the identity security problem What actually is a passkey? What makes passkeys phishing-resistant? HIPAA and compliance rules What’s next? Subscribe Today! Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast. We’re pleased to welcome back Eric Englebretson , Besler Holdings’ Vice President of Information Technology. In this episode, Eric will provide us with a glimpse into our next Hospital Finance Academy Webinar, the second in its Modern Identity Defense for Healthcare series, Passkeys in Practice , live on Wednesday, September 16th, at 1 PM Eastern Time. Welcome back, and thank you for joining us, Eric. Eric Englebretson: Thank you for having me yet again. Kelly: All right. Let’s go ahead and jump in. So, Eric, the last time you talked about identity attacks in healthcare. What can we expect in this second installment in this series? And why passkeys specifically? Eric: Well, Kelly, because if part one was about why attackers go after identities, part two is going to be about the single biggest fix we’ve seen in at least 15 years. Passwords are, and I can say this without hyperbole, one of the worst security tools we have for protecting a digital identity. And honestly, passkeys are the industry’s answer. Google, Microsoft, Apple, Amazon, PayPal, if you’ve logged into any of those lately, you’ve probably already been nudged to create one. And this session is going to take the mystery out of what’s actually happening when you do. Kelly: Yeah, no, I’ve seen a lot more passkeys myself lately, so this will be interesting for me too. So, we already have MFA. Isn’t that solving the identity security problem already? Eric: So, it does help, but it doesn’t solve it. SMS codes can get intercepted via either SIM swapping and just general insecurities in the protocols behind text messages. The one-time codes you get from apps like Google Authenticator, those can still be phished and replayed if someone tricks you into typing your password and code into a fake site. And then, of course, push-based MFA has what we call and what we identified in the last session as MFA fatigue where people just approve prompts to make them stop. That’s literally how Uber got breached, in fact. Passkeys sidestep all three because they’re inherently multi-factor: something you have, the device, plus something you are or know, like a biometric or a PIN. So, it’s one seamless step, nothing to fatigue approve and nothing to get intercepted and replayed. Kelly: Very, very interesting. So, Eric, in plain English, what actually is a passkey? Eric: And this is so fun because at its core, it’s really complicated, but it’s a pair of cryptographic keys. Don’t let your eyes glaze over when I say that. I’ll explain a little bit more in the session. And ultimately, of those keys, one lives on the website server and one lives on your device, and they never trade that secret part back and forth. So, think of it like a locked suggestion box. Anyone can drop a message in using the public key portion, but only the person holding the private key can open that message box and, in this case, sign something to prove that it’s really them. The signature is what gets checked, not a password, not your private key. So, the important bits don’t go back and forth where they could be intercepted. Kelly: I mean, it sounds easy enough. So, what actually makes passkeys phishing-resistant? I mean, it sounds like a big claim given how easily we can be tricked into giving away passwords and authenticator codes. Eric: It actually is a big claim, but I think it holds up. So, each passkey you create is bound to a specific domain, and that’s one of the important bits. So, if somebody builds a pixel-perfect clone of Microsoft.com at, let’s say, micronsoft.com and you don’t notice, your device actually won’t even offer the passkey. It actually simply won’t even respond. When implemented properly, there’s no password to type, so there’s nothing to divulge and put in the wrong place. And that one property right there basically neutralizes phishing and the adversary-in-the-middle attacks, which we talked about and were the star villains of our last session. Kelly: Very interesting. So, healthcare has HIPAA and compliance rules around all of this. Do passkeys actually check that box? Eric: So, this is great. They don’t actually just check it. They exceed it. So, HIPAA Security Rule requires verifying that a person accessing e-PHI is who they claim to be, but they don’t mandate a specific technology. So, passkeys deliver cryptographic proof of identity, and that eliminates the number one credential theft vector. And that also aligns with, and I’ll explain this as well in this session, something called NIST SP 800-63B. Again, don’t let your eyes glaze over. And basically, they have what are called authenticator levels. And these meet or even go up to the next level depending on whether or not you’re using hardware keys. And then for HHS’s own 405(d) program, they’ve been recommending FIDO2 and passkeys as a priority mitigation for healthcare specifically for quite a while now. So yes, definitely, this far exceeds the things that we need for HIPAA. Kelly: Well, that is great news. And I’m looking forward to learning more about that. So, this all sounds almost too good. What’s the catch? Eric: That’s a really fair question. I get it a lot. So, in this case, we’ve got– we’re building a front door that is genuinely rock solid, made out of metal. The catch is actually a backdoor here, account recovery. So as an example, let’s say you’re storing all your passkeys on your phone. If your phone dies and you lose your passkeys, what’s guarding your way back in? Because you’ve got to have one, right? Well, usually it’s a password reset email plus an SMS code. Well, that’s the absolute weakest link protecting the strongest lock we’ve ever built. We’ll dig into exactly how to close that gap in the full session, but that’s really the only downside.</...

