HEALTHCARE ACCESS SECURITY
Hospital Security Keys: Phishing-Resistant MFA for Electronic Medical Record Access
Protect access to electronic medical records and hospital information systems with YubiKey FIDO2 hardware security keys. Phishing-resistant authentication that is fast enough for clinical staff, works without batteries or network connectivity, and supports your obligations under Indonesia's Personal Data Protection Law and Ministry of Health Regulation 24/2022.
Since Ministry of Health Regulation No. 24 of 2022 took effect, healthcare facilities in Indonesia have been required to maintain medical records electronically. Digitalization accelerates care and interoperability, but it also shifts the point of risk: whoever controls the credentials of a doctor, nurse, or medical records officer effectively controls access to patient data. The security of electronic medical records now depends heavily on how strong user authentication really is.
At the same time, Law No. 27 of 2022 on Personal Data Protection classifies health data as specific (sensitive) personal data and obliges data controllers — hospitals included — to implement technical and organizational measures to secure personal data processing. A patient data breach carries legal and financial consequences, and it erodes the patient trust that healthcare fundamentally runs on.
The problem is that most cyberattacks on healthcare organizations start with credentials: phishing, password theft, and account misuse. MFA based on SMS OTPs or authenticator apps is better than passwords alone, but it can still be defeated by real-time phishing and notification fatigue. Hospital security keys built on the FIDO2 standard close this gap: cryptographic credentials are bound to the legitimate domain so they cannot be harvested on a fake site, and the physical key cannot be cloned remotely.
Why Conventional Authentication Falls Short in Hospitals
Credentials get shared in shift-based environments
Shared workstations, rapid shift changes, and clinical time pressure lead to passwords being shared or sessions left open. Audit trails blur, and accountability for medical record access becomes hard to enforce.
SMS OTPs and authenticator apps are still phishable
Modern phishing kits relay OTP codes to the legitimate system in real time, while push notifications get approved out of fatigue. Code-based second factors never verify the authenticity of the site the user is actually on.
Patient data is sensitive personal data with legal consequences
Indonesia's PDP Law classifies health data as specific personal data, mandates securing its processing, and provides administrative sanctions for violations. Regulation 24/2022 likewise requires electronic medical records to be operated with security and confidentiality.
Slow security controls get bypassed by clinical staff
Cumbersome login procedures in the ER or on the ward breed workarounds: passwords on sticky notes, sessions left open, borrowed accounts. Security that fights the clinical workflow ends up defeating itself.
YubiKey: Hardware Security Keys Built for Clinical Workflows
Phishing-resistant authentication with FIDO2/WebAuthn
Cryptographic credentials are bound to the legitimate service origin, so they simply do not work on look-alike sites. There is no code for an attacker to intercept, relay, or harvest.
Fast for clinicians: tap and go
Authenticating takes a touch on a USB port or an NFC tap — faster than typing an OTP. Ideal for shared workstations with frequent user switching.
Multi-protocol coverage for hospital systems
A single key supports FIDO2/WebAuthn, FIDO U2F, smart card (PIV), and OTP, securing web-based HIS/EMR platforms, Windows login, VPN, and Microsoft 365, Entra ID, or Google Workspace through your identity provider.
No battery, no network, built for the ward
YubiKeys need no battery or cellular connection, so they keep working in poor-signal areas like basement radiology. The rugged form factor survives being carried through every shift.
Lifecycle governance and certified options
DTI helps you design enrollment policies, backup keys, and centralized revocation for staff transfers and departures. Where higher assurance is required, the YubiKey FIPS Series is FIPS 140-2 validated.
DTI has guided organizations in Indonesia's regulated sectors — including healthcare and financial services — from design through full operational rollout of hardware security key authentication.
How Implementation Works at Your Hospital
System assessment and access mapping
We map your priority systems — EMR/HIS, identity provider, VPN, email, and clinical workstations — along with user roles and shift workflows. The result is a realistic authentication architecture and integration list, not assumptions.
Pilot with high-risk user groups
Rollout starts with the highest-impact accounts: IT administrators, medical records staff, pharmacy, and management. The pilot validates system compatibility, real-world login speed, and procedures for forgotten or lost keys.
Mass enrollment and recovery policies
Keys are distributed and enrolled unit by unit, each user with a backup key and an account recovery flow that does not reopen a social engineering hole. Short, practical training ensures adoption without disrupting care.
Operations, audit, and expansion
Once stable, policies are tightened progressively toward phishing-resistant MFA as the standard, with usage monitoring, key lifecycle management, and reporting ready for internal audits and compliance evidence.
Frequently Asked Questions
Do Indonesian regulations require hospitals to use hardware security keys?
No regulation explicitly mandates a specific authentication method. However, the PDP Law requires data controllers to implement technical safeguards for personal data — especially health data, which is classified as specific personal data — and Regulation 24/2022 requires electronic medical records to be kept secure and confidential. FIDO2 security keys are one recognized, phishing-resistant way to meet those obligations.
How is a security key different from SMS OTPs or authenticator apps?
OTPs and push approvals produce codes or confirmations that attackers can capture through phishing sites that relay them in real time. A FIDO2 security key performs a cryptographic check bound to the service's genuine domain, so authentication automatically fails on a fake site. It is also faster: a touch instead of typing a code.
Does this work for shared workstations used across shifts?
Yes — this is one of its strongest use cases. Each clinician carries their own key and simply inserts or taps it (NFC) to sign in as themselves, then ends the session when leaving. User switching stays fast, and you get an audit trail per individual rather than per computer.
What happens if a doctor or nurse loses their key?
Our standard practice is to enroll every user with a backup key, and a lost key is immediately revoked so it can no longer be used. Credentials cannot be extracted from the key, and without the associated account and PIN, a found key grants a stranger no access at all.
Can YubiKey integrate with the HIS or EMR system we already run?
The most common path is through an identity provider (such as Microsoft Entra ID, Google Workspace, or a SAML/OIDC-based IdP) acting as the front door, which protects web-based HIS/EMR applications without modifying them. Systems that natively support WebAuthn, smart card (PIV), or OTP can use YubiKey directly. Our assessment phase maps the integration route that fits you best.
Does the key need a battery, a companion app, or internet connectivity of its own?
No. A YubiKey is a passive device with no battery and no network module; it only responds when touched on a USB port or tapped via NFC. That makes it dependable in hospital areas with poor cellular signal and removes any dependency on clinicians' personal phones.
HEALTHCARE ACCESS SECURITY
Secure Your Hospital's Electronic Medical Record Access
Talk to the DTI team about your environment — from an authentication architecture assessment and a measured pilot to a hospital-wide YubiKey rollout. We help you build phishing-resistant MFA that aligns with Indonesia's PDP Law and MoH Regulation 24/2022 without slowing down clinical care.
