Compliance

HIPAA Password Requirements in 2027: One Login per Person, Two-Step Codes, and Medicaid Portal Rules

A person at a wooden desk holds a smartphone beside an open laptop, with a notebook and pen to one side
Photo: Alejandro Escamilla, Wikimedia Commons, CC0 1.0, cropped

Overview

HIPAA sets no password length, character mix, or change schedule. For a covered entity or business associate it requires a unique login for each person (45 CFR 164.312(a)(2)(i)) and a way to confirm who is signing in (164.312(d)). HIPAA does not yet require two-step codes, but Texas, Alabama, Georgia, and New York Medicaid portals and MTM's Rhode Island portal already do.

  • HIPAA sets no password length or expiration. It requires one unique login per person and a way to verify who is signing in.
  • NIST's final guideline of July 2025 asks for 15 characters when a password stands alone, and for no forced periodic changes.
  • Texas, Alabama, Georgia, New York, and MTM's Rhode Island portal already require a second sign-in step.
  • Texas now requires a new TMHP password every 90 days, starting August 24, 2026, which is stricter than NIST.
  • HHS proposed requiring multi-factor login in January 2025. Its agenda targets July 2027, and nothing is final.

If you, your biller, and your dispatcher all sign in to one Medicaid portal with one password, you have the problem this page covers. HIPAA does not tell you how long a password must be or how often to change it. It does tell you to know who did what, and a shared login makes that impossible. Meanwhile, state portals and brokers keep adding their own sign-in rules, some stricter than any federal one.

What HIPAA requires for passwords

The Security Rule applies to covered entities and business associates, so start with whether that is your company. If it is, these are the parts of the rule that touch logins (45 CFR 164.308 and 164.312, as shown in the eCFR on October 2, 2026):

  • Unique user identification (required). Assign a unique name or number to each user so activity can be traced to a person (164.312(a)(2)(i)).
  • Person authentication (required standard). Use procedures to verify that a person seeking access to rider information is the one claimed (164.312(d)). The rule names no method.
  • Activity review (required). Regularly review records of system activity, such as audit logs and access reports (164.308(a)(1)(ii)(D)).
  • Emergency access (required). Have a procedure for reaching rider information during an emergency (164.312(a)(2)(ii)).
  • Password management (addressable). Keep procedures for creating, changing, and safeguarding passwords (164.308(a)(5)(ii)(D)).
  • Log-in monitoring (addressable). Keep procedures for monitoring log-in attempts and reporting discrepancies (164.308(a)(5)(ii)(C)).
  • Automatic logoff (addressable). End a session after a set time of inactivity (164.312(a)(2)(iii)).

Addressable does not mean optional. You decide whether each one is reasonable and appropriate for your company. If it is, you put it in place. If it is not, you write down why and, where one is reasonable, use an equivalent alternative (164.306(d)).

Nothing in the rule sets a minimum length, a mix of characters, or a change schedule. When HHS proposed an update on January 6, 2025, it said it did not propose that passwords meet a particular standard, because best practices for password configuration may change over time. So the number in your policy is your call, and the best number to borrow is NIST’s.

A shared login breaks the unique user rule, because the portal can no longer tell who did what. Your biller and your dispatcher each need their own.

What NIST says a good password is

HIPAA adopts no password standard, so look to the one federal agencies use. The National Institute of Standards and Technology (NIST) published the final version of its digital identity guideline, SP 800-63B-4, in July 2025, replacing the 2020 edition. It is written for government systems, so no ride company must follow it. It is the current edition of the federal password guidance, and HHS’s 2025 proposal says passwords should follow “the current recommendations of authoritative sources” without defining the term.

NIST asks for these:

  • Length first. A password used alone must be at least 15 characters. One used only together with a second factor may be shorter, but at least 8. Systems should accept at least 64 characters.
  • No composition rules. Do not force a mix of capitals, numbers, and symbols.
  • No forced changes. Do not make people change passwords on a schedule. Force a change when there is evidence a password was compromised.
  • A blocklist check. Compare each new password with lists of common and breached passwords, and with the service name and the username.
  • No hints or security questions. Systems must not keep a hint that someone who has not signed in can see, and must not ask questions like a first pet’s name.
  • Password managers allowed. Systems should let people use a password manager and paste into the field.

For your office, that becomes one sentence: at least 15 characters, never reused across accounts, kept in a password manager instead of on a sticky note, and changed only when you suspect someone else has it. Part 9 of the NEMT HIPAA policy template has a blank for password length, and 15 is a number you can defend.

Portals you do not control may set stricter rules than NIST. The Texas Medicaid & Healthcare Partnership (TMHP) now makes providers change their password every 90 days (below). Where a portal’s rule is stricter, follow the portal. Your own email, dispatch, and billing accounts can follow NIST.

Two-step codes: not required by HIPAA yet

HIPAA’s authentication standard does not name multi-factor authentication. HHS proposed on January 6, 2025 (90 FR 898) to require it on all technology assets in a company’s relevant systems. The proposal allows narrow exceptions: a device that cannot support it while you follow a written plan to move the data, an emergency when it is not possible, and certain FDA-authorized medical devices. It defines multi-factor as at least two different kinds of proof, such as something you know and something you have. A password plus a PIN is not multi-factor, because both are things you know.

The same proposal would require unique passwords instead of factory defaults, and it would require ending a departing worker’s access as soon as possible and no later than one hour after the job ends. As proposed, a final rule would take effect 60 days after publication, and companies would generally have 180 days after that to comply (45 CFR 160.105). HIPAA for NEMT providers lists the rest of what HHS proposed.

HHS’s 2026 regulatory agenda lists final action as a long-term item with a target of July 2027 (RIN 0945-AA22). As of October 6, 2026, the Federal Register shows only the proposal. Plan for it, but do not treat it as law yet.

A second step usually comes in one of three forms: a code from an authenticator app, a code sent by text, or a code sent by email. Where a portal offers an authenticator app, choose it. NIST’s guideline says email must not be used to deliver a sign-in code (it calls this out-of-band authentication) and calls codes sent by text message or phone call restricted, and Georgia’s portal guide says current federal guidance does not recommend text messages because they are not secure.

The portals that already require them

HIPAA may not require a second step, but these portals do. Which ones reach you depends on how your state pays for rides. Texas and New York portals are where ride providers enroll with Medicaid, and Rhode Island’s applies to providers in MTM Health’s program. In Alabama the NET program pays transporters without Medicaid claims, and in Georgia a ride company signs with the broker instead of enrolling in Medicaid, so those two portals reach you only if you have a login there for other Medicaid work.

Portal Who signs in Second step Since
Texas: TMHP IAMOnline Texas Medicaid providers Email code, or an authenticator app June 12, 2026
Alabama: Interactive Web Portal Providers with a portal login Authenticator app code December 2024
Georgia: GAMMIS Medicaid providers and their billing agents Authenticator app code Scheduled for November 2022 to March 2023
New York: Provider Services Portal Providers enrolling in Medicaid Set up at first sign-in Not dated on the state’s page
Rhode Island: MTM Link NEMT providers in MTM’s program Code by text or email Not dated in the July 1, 2026 handbook

Texas: four releases and a 90-day rule

TMHP moved its provider applications behind one login, called TMHP IAMOnline, in four releases. On June 12, 2026 it moved the enrollment application (PEMS) and electronic remittance advice. On July 10 it moved TexMedConnect, the claims application, along with fee schedules and remittance and status reports. On August 3 it moved the Medicaid client portal, document uploads, the provider message dashboard, and My Account. On August 24 it moved Custom Reports and the long-term care and electronic visit verification portals. Applications not yet moved keep the old login, with the new password.

Each provider activates by following the email TMHP sends, setting a password, and registering multi-factor authentication within seven days of receiving it. Providers are enrolled in email codes automatically and can add an authenticator app. If the seven days pass, call the EDI Help Desk at 888-863-3638 to have the email sent again.

From August 24, 2026, providers must change their password every 90 days and use each application at least once every 90 days, or the account or application is deactivated. TMHP emails reminders after 80, 85, and 89 days of inactivity, and the help desk can reactivate access. That is stricter than NIST, so put a calendar reminder on the biller who only signs in at month end. See the Texas guide for how enrollment works.

Alabama: phases by account type

Alabama Medicaid’s ALERT of December 13, 2024 scheduled multi-factor sign-in for its Interactive Web Portal in phases by account type. The first accounts started in December 2024 and January 2025. Provider administrator accounts were scheduled for February 2025, provider clerk accounts for March, and all other accounts for April. The ALERT of March 31, 2025 says the requirement covers every account type and that the state’s contractor was turning it on for a select number of usernames at a time.

Users enter a six-digit code from a time-based authenticator app each time they sign in, unless their last successful sign-in was within 30 minutes. Setup shows a QR code and a secret code at first login. For help, call the Provider Assistance Center at 1-800-688-7989, option 1, then option 2. Alabama’s NET program pays transporters without Medicaid claims, so you may never need this login (see the Alabama guide). It matters if you also bill Medicaid as another kind of provider.

Georgia: delegate access instead of sharing

Georgia’s FAQ for its Medicaid portal, GAMMIS, is dated October 2022. It scheduled multi-factor sign-in for new user IDs from November 29, 2022, for existing IDs between then and February 28, 2023, and for all provider accounts on March 1, 2023. As of October 6, 2026 the portal’s training page still lists that FAQ, with two more multi-factor guides dated November and December 2022. Each user ID has its own code, and no code can serve two IDs.

The FAQ shows how to avoid sharing. Each person who works for a provider creates a billing agent user ID. The provider ID then delegates super agent permission to at least two administrators, who can add and remove access for everyone else. Each person keeps one user ID and one code. If an administrator leaves and no backup administrator exists, the help desk must set up a new user ID, and if it was the master provider ID, every delegation has to be repeated. The FAQ also says an ID locks after 60 days of inactivity and that the password reset link works only within 180 days of the last password change. A Georgia ride company signs with the broker instead of enrolling in Medicaid, so see the Georgia guide before you assume this portal applies to you.

New York: set up before first access

New York’s eMedNY Provider Services Portal, where providers enroll and update their Medicaid file, is reached through a Health Commerce System account or a NY.gov business account. Its landing page says that if multi-factor authentication has not been set up, you are prompted to set it up before you reach the portal the first time. Creating the account includes an identity check, and the state says the documents and photos are not kept. See the New York guide.

MTM Health’s Rhode Island handbook, last updated July 1, 2026, has you sign in to MTM Link with an email address and passcode, then choose a six-digit code by text or email. Codes expire after 10 minutes, three wrong tries mean a 10-minute wait, and “remember this device for 30 days” covers only the device where you ticked it. The same login also works in the driver app. See MTM Health for its other states.

Set it up so nobody shares a login

  1. List every account. Write down each broker portal, state Medicaid portal, billing tool, dispatch tool, and company email account, and who uses it.
  2. One person, one login. Use each portal’s way to add users or delegate access, and ask its help desk how if you cannot find it. Georgia’s model shows the idea: each person has their own user ID, and the provider ID delegates access to them.
  3. Put the second step on the user’s own phone. Never on the owner’s phone for the whole office. In Georgia’s portal each user ID needs its own code, and when the person holding a code leaves, the help desk can change that account’s email only if the caller gives the current six-digit code along with other details that prove who they are.
  4. Keep two administrators on every portal. One person holding the only administrator login, and the only phone with its code, is the setup that locks a company out.
  5. Pick the authenticator app wherever the portal offers a choice.
  6. Write the rule into your policy. Password length, a password manager, change only on suspicion, and a yearly review of who has access. The HIPAA risk assessment template covers the same ground.
  7. Set reminders for portals that deactivate idle accounts: 90 days at TMHP and 60 days in GAMMIS.
  8. Look at the activity. HIPAA requires regular review of system activity records, so check who signed in and when, and ask about anything you do not recognize.

When someone leaves or loses a phone

HIPAA asks for procedures to end access when a worker’s job ends (164.308(a)(3)(ii)(C), addressable). With second steps, the phone counts as part of the login, so removing a person means closing their user in every portal and taking their phone off any sign-in codes the same day. The employee termination checklist has the full list, and the remote dispatcher guide covers logins for staff working from home.

A lost phone with an authenticator app is a lockout and a risk. Call the portal’s help desk to reset the code. Georgia’s help desk, for example, resets the account’s code so the user can set it up again on a new phone, as long as the caller still knows the password. If the phone also held rider information, treat it as a possible breach and follow the data breach steps.

Frequently asked questions

Does HIPAA require a specific password length or complexity?

No. The Security Rule lists password management as an addressable safeguard, meaning procedures for creating, changing, and safeguarding passwords (45 CFR 164.308(a)(5)(ii)(D)). It sets no length, character mix, or change schedule. HHS said in its January 6, 2025 proposal that it did not propose a particular password standard because best practices may change over time. NIST's final guideline of July 2025 asks for at least 15 characters when a password is used alone.

How often does HIPAA require password changes?

On no set schedule. NIST's guideline says systems should not require periodic changes and should force one only when there is evidence a password was compromised. Some portals set their own rule anyway. From August 24, 2026, Texas's TMHP IAMOnline requires a password change every 90 days. Follow the portal's rule for that portal, and use NIST's approach for your own accounts.

Does HIPAA require multi-factor authentication?

Not today. Section 164.312(d) requires procedures to verify that a person is who they claim to be and names no method. HHS proposed on January 6, 2025 to require multi-factor authentication on all technology assets in relevant systems, with limited exceptions. HHS's regulatory agenda lists final action for July 2027, and as of October 6, 2026 the Federal Register shows no final rule. Many portals and brokers already require it.

Can my biller and dispatcher use my login to the Medicaid portal?

No. HIPAA requires a unique name or number for each user so activity can be traced to a person (45 CFR 164.312(a)(2)(i)). Portals back this up. Georgia's portal guide says each person should have only one user ID, and it tells providers to delegate access to billing agents instead of handing out one login. Ask the portal's help desk how to add users.

Is a text message code good enough as a second step?

Use an authenticator app where a portal offers a choice. Georgia's guide says current federal guidance does not recommend text messages as a second step because they are not secure. NIST's guideline calls codes sent by text message or phone call restricted, meaning the organization must accept the added risk, and says email must not be used to deliver sign-in codes. Texas still starts providers on email codes and lets them add an authenticator app, so follow each portal's own options.

What happens if a portal account sits unused?

Some portals shut it off. From August 24, 2026, TMHP deactivates a TMHP IAMOnline account or an application after 90 days without use, with reminder emails at 80, 85, and 89 days, and the EDI Help Desk at 888-863-3638 can reactivate it. Georgia's portal FAQ, dated October 2022, says a user ID locks after 60 days of inactivity and the portal's help desk can reopen it.

When would HHS's proposed Security Rule take effect?

Not before a final rule exists. As proposed, a final rule would take effect 60 days after publication, and regulated entities would generally have until 180 days after that to comply (45 CFR 160.105). HHS's agenda lists July 2027 for final action. Turning on two-step codes and giving each person a login now puts you ahead of the proposal either way.

Official resources

Join the NEMT Guide Digest

Our free newsletter for NEMT owners: broker changes, new state rules, and new guides, sent when there is news worth your time. No spam.