Benchmark: User Identification and Authentication
Description
User identification and authentication play a crucial role. This involves implementing strong measures to verify the identity of users accessing electronic protected health information (ePHI). To comply with these standards, organizations should establish unique user IDs and enforce the use of strong passwords or passphrases. Additionally, implementing multi-factor authentication adds an extra layer of security by requiring users to provide additional verification, such as a code sent to their mobile device, in addition to their login credentials. By implementing robust user identification and authentication practices, organizations can ensure that only authorized individuals can access ePHI, reducing the risk of unauthorized disclosure and maintaining compliance with HIPAA and HITRUST 9.2 regulations.
Usage
Install the mod:
mkdir dashboardscd dashboardspowerpipe mod initpowerpipe mod install github.com/turbot/steampipe-mod-azure-compliance
Start the Powerpipe server:
steampipe service startpowerpipe server
Open http://localhost:9033 in your browser and select User Identification and Authentication.
Run this benchmark in your terminal:
powerpipe benchmark run azure_compliance.benchmark.hipaa_hitrust_v92_user_identification_and_authentication
Snapshot and share results via Turbot Pipes:
powerpipe benchmark run azure_compliance.benchmark.hipaa_hitrust_v92_user_identification_and_authentication --share
Benchmarks
- Non-organizational users (all information system users other than organizational users, such as patients, customers, contractors, or foreign nationals), or processes acting on behalf of non-organizational users, determined to need access to information residing on the organization's information systems, are uniquely identified and authenticated
- The organization requires that electronic signatures, unique to one individual, cannot be reused by, or reassigned to, anyone else
- Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records
- Signed electronic records shall contain information associated with the signing in human-readable format