Passkeys in Practice Webinar Summary

Defending Against Identity Attacks – Passkeys in Practice Webinar Summary
Based on Passkeys in Practice, Part 2 of the Modern Identity Defense for Healthcare Webinar Series, presented by Eric Englebretson, Vice President of IT, Besler Holdings.
This webinar series discusses modern identity security challenges and solutions, emphasizing MFA, passkeys, and proactive defense strategies in healthcare.
Healthcare organizations continue to pay the highest price for identity-related breaches. Average incident costs now range from $6–10 million, and more than 80% of confirmed healthcare breaches involve stolen or compromised credentials (HHS HC3 / Verizon DBIR).
Staff routinely juggle 40–100+ passwords across EHR, patient portals, insurance, lab, and scheduling systems. The result is password fatigue, reuse, sticky notes, and sharing—exactly the conditions attackers exploit.
Traditional multi-factor authentication (MFA) has not solved the problem. Most MFA still sits on top of a password, leaving every password weakness intact. Passkeys change that equation.
Why Passwords and Traditional MFA Keep Failing
| Threat | How Passwords Fail | How Traditional MFA Still Falls Short |
| Phishing / Adversary-in-the-Middle | Staff enter credentials on fake login pages | TOTP codes can be phished; SMS is vulnerable to SIM-swapping. |
| Credential stuffing | Same password works across sites | MFA reduces overall threat, but doesn’t eliminate reuse risk. |
| Database breaches | Stored hashes can be cracked | Password hashes remain at risk. |
| Password sharing among clinical staff | Verbal sharing or written notes | MFA doesn’t prevent sharing of the first factor. |
| Brute-force / spray attacks | Weak passwords guessed | Still possible against the password layer. |
| Keylogger malware | Keystrokes capture secrets | Password is still typed. |
Passkeys are inherently multi-factor—something you have (the device) plus something you are or know (biometric or PIN)—in a single, phishing-resistant step. Nothing sensitive ever leaves the device.
What are Passkeys?
A passkey is the credential portion of the open FIDO2/WebAuthn standard. It replaces passwords with public-key cryptography.
- Your device generates a unique key pair for each website or application.
- The private key never leaves the device (Secure Enclave on Apple, TPM on Windows, TEE/StrongBox on Android, or a hardware security key).
- The public key is stored on the server. It’s useless without the matching private key.
- Sign-in occurs with a biometric glance, fingerprint, PIN, or security-key tap. No typing, no shared secret transmitted.
Core Security Properties
- Phishing-resistant by design (bound to the exact domain; the browser/OS will not offer the passkey on a look-alike site).
- No replay attacks (unique cryptographic challenge/response every session).
- No credential stuffing (each passkey is unique per site).
- Database breach impact is near-zero (only public keys are stored).
- User friction is dramatically lower than passwords + MFA.
Three Models of Passkeys and Where They Live
| Type | Best for | Storage | Key Characteristics |
| Synced passkeys | General staff, personal accounts | iCloud Keychain, Google Password Manager, Microsoft account | Convenient across devices; private key transits consumer cloud |
| Device-bound passkeys | Privileged, admin, or compliance-regulated accounts | Never leaves the specific device | Maximum security; recommended for healthcare via MDM/IdP policy |
| Hardware security keys (YubiKey, etc.) | Shared workstations, high-assurance recovery | On-key storage | Private key never leaves the physical device |
Most organizations can adopt a hybrid approach: synced passkeys for the general workforce and device-bound or hardware keys for privileged access.
HIPAA and Healthcare Compliance Alignment
The HIPAA Security Rule (45 CFR § 164.312(d)) requires verification that a person seeking ePHI access is the one claimed. It doesn’t mandate a specific technology. Passkeys meet and exceed the requirement through:
- Cryptographic proof of identity.
- Phishing resistance.
- Device-bound non-repudiation.
- Audit-friendly logging.
- Alignment with NIST SP 800-63B AAL2/AAL3.
HHS 405(d) and HC3 explicitly recommend FIDO2/passkeys as a defense against phishing.
Creating and Using a Passkey (Step-by-Step)
Registration (one-time)
- Go to the account’s security settings.
- Choose “Create a passkey” or “Set up passkey.”
- Confirm with biometric, PIN, or security key.
- The passkey is stored in the platform’s passkey manager.
Sign-in
- Enter username or select account.
- Device detects an available passkey and prompts.
- Approve with Face ID, fingerprint, PIN, or tap.
- Signed in—no password typed, no code copied.
Best practice: Register at least two passkeys (primary device + backup device or hardware key) where possible, so a lost phone doesn’t lock you out.
Downsides and How to Mitigate Them
The front door is extraordinarily strong, but the back door—account recovery—is often still a 20-year-old email + SMS reset. Do not guard the strongest authentication with the weakest recovery method.
- Disable SMS-based recovery wherever possible.
- Prefer TOTP authenticator apps or additional passkeys for recovery.
- For enterprises, enforce device-bound passkeys via IdP/MDM and pre-plan a documented loss/recovery process.
Passkeys do not replace endpoint malware protection, screen locks, network controls, or awareness of non-authentication scams (BEC, invoice fraud). They’re a massive leap for authentication specifically; Prevent, Detect, and Respond still all matter.
Key Takeaways for IT and Finance Leaders
- Passkeys are inherently multi-factor and phishing-resistant by design.
- Passwords remain the weakest link; passkeys eliminate them.
- Built on open FIDO2/WebAuthn standards (supported by Apple, Google, Microsoft).
- Organizations should prioritize device-bound, enterprise-managed passkeys for privileged accounts.
- Harden account recovery so it’s at least as strong as the passkey itself.
Next Steps for Your Organization
- Enable passkeys on every account that already offers them (Google, Microsoft 365, many EHR portals).
- Pilot device-bound passkeys for a small, privileged group via your identity provider.
- Update onboarding checklists to include passkey enrollment.
- Review and strengthen account-recovery flows.
Ready to move beyond passwords? Watch the full webinar replay and/or connect with the Besler Holdings / Sypher Security team to discuss implementing cybersecurity best practices for your team.
Access the Modern Identity Defense for Healthcare Webinar Series
Part 1: Defending Against Identity Attacks | On-Demand Now
Part 2: Passkeys in Practice | On-Demand Now



