Under active development Content is continuously updated and improved · Last updated Feb 18, 2026, 2:55 AM UTC

500.12(a)500.12(a)

>Control Description

Multi-factor authentication shall be utilized for any individual accessing any information systems of a covered entity, unless the covered entity qualifies for a limited exemption pursuant to section 500.19(a) of this Part in which case multi-factor authentication shall be utilized for:

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.