← Back to All Podcasts
Modern Identity Defense for Healthcare Series—Passkeys in Practice
In this episode, Eric Englebretson, Besler Holdings’ VP of Information Technology, provides us with a glimpse into our next Hospital Finance Academy Webinar, the second in the Modern Identity Defense for Healthcare series, Passkeys in Practice, live on Wednesday, September 16, at 1 PM ET.
Highlights of this episode include:
- What we can expect in this second installment in this series?
- Why passkeys specifically?
- How MFA isn’t solving the identity security problem
- What actually is a passkey?
- What makes passkeys phishing-resistant?
- HIPAA and compliance rules
- What’s next?
Kelly Wisness: Hi, this is Kelly Wisness. Welcome back to the award-winning Hospital Finance Podcast. We’re pleased to welcome back Eric Englebretson, Besler Holdings’ Vice President of Information Technology. In this episode, Eric will provide us with a glimpse into our next Hospital Finance Academy Webinar, the second in its Modern Identity Defense for Healthcare series, Passkeys in Practice, live on Wednesday, September 16th, at 1 PM Eastern Time. Welcome back, and thank you for joining us, Eric.
Eric Englebretson: Thank you for having me yet again.
Kelly: All right. Let’s go ahead and jump in. So, Eric, the last time you talked about identity attacks in healthcare. What can we expect in this second installment in this series? And why passkeys specifically?
Eric: Well, Kelly, because if part one was about why attackers go after identities, part two is going to be about the single biggest fix we’ve seen in at least 15 years. Passwords are, and I can say this without hyperbole, one of the worst security tools we have for protecting a digital identity. And honestly, passkeys are the industry’s answer. Google, Microsoft, Apple, Amazon, PayPal, if you’ve logged into any of those lately, you’ve probably already been nudged to create one. And this session is going to take the mystery out of what’s actually happening when you do.
Kelly: Yeah, no, I’ve seen a lot more passkeys myself lately, so this will be interesting for me too. So, we already have MFA. Isn’t that solving the identity security problem already?
Eric: So, it does help, but it doesn’t solve it. SMS codes can get intercepted via either SIM swapping and just general insecurities in the protocols behind text messages. The one-time codes you get from apps like Google Authenticator, those can still be phished and replayed if someone tricks you into typing your password and code into a fake site. And then, of course, push-based MFA has what we call and what we identified in the last session as MFA fatigue where people just approve prompts to make them stop. That’s literally how Uber got breached, in fact. Passkeys sidestep all three because they’re inherently multi-factor: something you have, the device, plus something you are or know, like a biometric or a PIN. So, it’s one seamless step, nothing to fatigue approve and nothing to get intercepted and replayed.
Kelly: Very, very interesting. So, Eric, in plain English, what actually is a passkey?
Eric: And this is so fun because at its core, it’s really complicated, but it’s a pair of cryptographic keys. Don’t let your eyes glaze over when I say that. I’ll explain a little bit more in the session. And ultimately, of those keys, one lives on the website server and one lives on your device, and they never trade that secret part back and forth. So, think of it like a locked suggestion box. Anyone can drop a message in using the public key portion, but only the person holding the private key can open that message box and, in this case, sign something to prove that it’s really them. The signature is what gets checked, not a password, not your private key. So, the important bits don’t go back and forth where they could be intercepted.
Kelly: I mean, it sounds easy enough. So, what actually makes passkeys phishing-resistant? I mean, it sounds like a big claim given how easily we can be tricked into giving away passwords and authenticator codes.
Eric: It actually is a big claim, but I think it holds up. So, each passkey you create is bound to a specific domain, and that’s one of the important bits. So, if somebody builds a pixel-perfect clone of Microsoft.com at, let’s say, micronsoft.com and you don’t notice, your device actually won’t even offer the passkey. It actually simply won’t even respond. When implemented properly, there’s no password to type, so there’s nothing to divulge and put in the wrong place. And that one property right there basically neutralizes phishing and the adversary-in-the-middle attacks, which we talked about and were the star villains of our last session.
Kelly: Very interesting. So, healthcare has HIPAA and compliance rules around all of this. Do passkeys actually check that box?
Eric: So, this is great. They don’t actually just check it. They exceed it. So, HIPAA Security Rule requires verifying that a person accessing e-PHI is who they claim to be, but they don’t mandate a specific technology. So, passkeys deliver cryptographic proof of identity, and that eliminates the number one credential theft vector. And that also aligns with, and I’ll explain this as well in this session, something called NIST SP 800-63B. Again, don’t let your eyes glaze over. And basically, they have what are called authenticator levels. And these meet or even go up to the next level depending on whether or not you’re using hardware keys. And then for HHS’s own 405(d) program, they’ve been recommending FIDO2 and passkeys as a priority mitigation for healthcare specifically for quite a while now. So yes, definitely, this far exceeds the things that we need for HIPAA.
Kelly: Well, that is great news. And I’m looking forward to learning more about that. So, this all sounds almost too good. What’s the catch?
Eric: That’s a really fair question. I get it a lot. So, in this case, we’ve got– we’re building a front door that is genuinely rock solid, made out of metal. The catch is actually a backdoor here, account recovery. So as an example, let’s say you’re storing all your passkeys on your phone. If your phone dies and you lose your passkeys, what’s guarding your way back in? Because you’ve got to have one, right? Well, usually it’s a password reset email plus an SMS code. Well, that’s the absolute weakest link protecting the strongest lock we’ve ever built. We’ll dig into exactly how to close that gap in the full session, but that’s really the only downside.
Kelly: Okay. Good to know. So, if someone only takes one thing away from this episode before they join us for the live webinar, what should it be?
Eric: Ultimately, it’s that passkeys aren’t just a nice-to-have. For healthcare organizations, they’re one of the most practical wins available right now against phishing, credential stuffing, and the account takeover attacks that dominate breach reports. In the full session, we’ll walk through the different types of passkeys, where they actually live on your device, device-bound versus synced trade-offs for enterprise deployments, and really an overview of creating and using one. I think it’s going to be well worth your time.
Kelly: Yeah. I think so, too. I think this is going to be a great webinar. Well, thank you so much for joining us, Eric, and for giving us this glimpse into Hospital Finance Academy’s free webinar, Passkeys in Practice, that’s going to be live Wednesday, September 16th, at 1 PM Eastern Time. And as a bonus, you can also earn CPE. Thanks again, Eric.
Eric: Absolutely.
Kelly: Wow, sounds like things are always changing in this space for sure. Well, thank you so–
Eric: Absolutely.
Kelly: And thank you all for joining us for this episode of The Hospital Finance Podcast. Until next time…
[music] This concludes today’s episode of The Hospital Finance Podcast. For show notes and additional resources to help you protect and enhance revenue at your hospital, visit besler.holdings/podcasts. The Hospital Finance Podcast is a production of Besler Holdings.
If you have a topic that you’d like us to discuss on The Hospital Finance Podcast or if you’d like to be a guest, drop us a line at update@besler.com.