Digital health services have become an integral part of the patient journey. Nearly two-thirds of individuals nationwide report being offered and accessing online medical records or patient portals. Proxy or caregiver access has also more than doubled in recent years, as electronic health information exchange continues to increase among patients, caregivers and providers.¹
Patient online access expectations are evolving just as quickly. Today’s consumers are accustomed to highly personalized virtual experiences across banking, retail and entertainment. Whether scheduling appointments, accessing medical records, joining telehealth visits or communicating with care teams, they increasingly expect the same level of convenience from digital healthcare interactions. Research found that one in four survey respondents would switch doctors to get access to virtual care.²
For hospitals and health systems, the digital front door is no longer a single patient portal. It includes online scheduling, digital registration, account creation, account recovery and a growing range of self-service healthcare experiences. As your digital engagement expands, so does your need to establish trust before access is granted.
When an individual creates an account, attempts to recover access credentials or logs in to access health information, you must determine whether the individual is who they claim to be. Most of these interactions are legitimate. Some are not.
The challenge is many digital interactions appear routine on the surface. A patient creating an account or recovering access credentials to view information may seem like an everyday occurrence. Behind the scenes, you must decide whether access should be granted and whether the interaction presents signs of risk.
The need to make digital trust decisions is the challenge behind healthcare’s expanding digital front door. As digital engagement grows, hospitals and health systems are making more of these trust decisions every day. Your healthcare identity verification must support that growth without creating unnecessary friction for trusted patients and caregivers.
As healthcare’s digital front door expands, identity threats are becoming harder to detect. Bad actors are increasingly using more sophisticated tactics to target key touchpoints across the online journey.
Three types of identity threats are especially important for healthcare organizations to understand and recognize:
Deepfake attacks use AI and machine learning to generate or alter realistic images, videos and audio to impersonate trusted individuals. Deepfakes are no longer a fringe concern, as 85% of identity threats in 2024 involved deepfakes or generative AI tools.³
Synthetic identities use a combination of real credentials, such as stolen Social Security numbers and fabricated personally identifiable information to create a persona that appears to be legitimate. More than one in 10 global threat events now involve a synthetic identity, an eightfold year-over-year increase.⁴
Account takeovers occur when bad actors gain unauthorized access to trusted patient accounts using stolen or compromised credentials, allowing them to access sensitive information or impersonate legitimate users.
The common thread among the top identity threats for healthcare organizations is that many can look legitimate. The challenge is no longer identifying obvious identity fraud. The challenge is confidently establishing trust when suspicious activity increasingly resembles normal behavior.
Passwords and traditional verification methods still play an important role, but they were not designed to address today’s identity threats on their own.
You need more than a single piece of information to make confident trust decisions. Identity information, device intelligence, risk indicators and additional verification signals can provide valuable context during critical moments such as account creation and account recovery. A password may be correct. A device may appear familiar. A recovery request may look routine. When evaluated together, however, these signals can help you build a more complete picture of identity risk before granting access.
Evaluating multiple identity signals is especially important for your patient portal security. Too much friction can discourage digital engagement. Too little security can increase exposure to identity fraud, account takeover and unauthorized access. The goal is not simply preventing fraud. The goal is to create a friction-right experience that supports both secure patient access and a positive digital experience.
As digital access expands, ask yourself:
The answers increasingly depend on a healthcare organization’s ability to establish trust using more than a single identity signal or verification step.
Driven by an AI-fueled increase in sophistication and automation, today’s identity threats are evolving faster than passwords and static verification checks were designed to handle. Nearly half of Americans have reported a password stolen in the past year.⁵
To keep pace with identity threats, hospitals and health systems need identity verification capabilities embedded within existing healthcare workflows, supported by digital identity intelligence that can evaluate multiple signals in context.
Identity Proofing for MyChart from LexisNexis® Risk Solutions delivers multi-signal identity intelligence that verifies identities faster, applies smarter scrutiny and strengthens access decisions across account creation and account recovery workflows.
Sources: