Most HIPAA security work focuses on the systems staff use — the EHR, email, the front-desk workstations. The one login screen almost nobody revisits after go-live is the one facing the public: your patient portal. And that’s exactly the login attackers are hitting the hardest, because they don’t need to break in. They just need patients who reused a password.
What’s actually happening
Credential stuffing attacks account for a median of 19% of all login attempts across consumer-facing portals, and only about 49% of the average person’s passwords are actually unique. Attackers take username-and-password lists leaked from unrelated breaches — a retailer, a social media site, anything — and run them against thousands of other login pages automatically, including patient portals. They aren’t guessing or cracking anything. They’re just checking whether a patient reused their Target password on your scheduling and billing portal.
A portal is an attractive target precisely because it sits in one place: PHI, insurance details, appointment history, and billing information, all behind a login that’s often protected with nothing more than a password.
Why this is a bigger deal than it looks
It doesn’t take a sophisticated breach to cause real damage. A single successful login gives an attacker a patient’s chart, insurance ID, and enough personal detail to attempt identity theft or insurance fraud — and if that account can request prescription refills or message a provider, the damage isn’t limited to data exposure. Scale matters too: the Change Healthcare breach traced back to a single compromised credential with no MFA behind it, and the industry-wide response cost is estimated at $2.3–2.45 billion. Patient portals don’t need a nation-state attacker to become a serious liability; they need one unprotected login and an automated script.
The HIPAA angle regulators are watching
A recent OCR investigation signaled that the Security Rule may require covered entities to take affirmative steps — including enforcing unique passwords and blocking credential stuffing — rather than treating it purely as a patient behavior problem. In other words, “the patient chose a weak password” isn’t a safe harbor. Regulators increasingly expect the practice to have technical controls in place regardless of what password a patient picks.
What to actually do about it
- Turn on multi-factor authentication for the patient portal, not just staff logins — a stolen password alone should never be enough.
- Rate-limit login attempts and use bot/CAPTCHA detection to slow down automated credential-stuffing tools.
- Monitor for anomalous login patterns — many failed attempts across many accounts in a short window is a clear stuffing signature.
- Force a password reset when a patient’s email shows up in a known third-party breach, rather than waiting for a complaint.
- Review your EHR or portal vendor’s authentication settings — many were configured once at go-live and never revisited.
Where ACS fits in
Most practices have never checked whether their patient portal even supports MFA, let alone whether it’s turned on. That’s exactly the kind of gap we look for during a free IT and HIPAA assessment — we’ll show you where your portal’s authentication actually stands and what it would take to close the gap.


