Most account takeovers in healthcare organizations start the same way: someone enters a password on a fake sign-in page, and a criminal uses it from another continent a few hours later. Multi-factor authentication helps, but it is not the whole answer. Conditional Access, a feature in Microsoft 365 licensing that many small operators already pay for and never configure, lets you decide when a sign-in is trustworthy enough to proceed.
The idea is simple. Instead of treating every sign-in identically, the system looks at the context: where the person is, what device they are using, which application they want, and how risky the sign-in looks. Normal activity sails through. Unusual activity gets blocked or challenged. Done well, your nurses and front-desk staff barely notice it exists.
Every rule has three parts: who it applies to, what they are trying to reach, and what happens when conditions are met. The outcome can be to allow, require MFA, require a compliant device, or block outright.
Think of it as a bouncer with a checklist rather than a locked door. A user signing in from the office on a managed laptop gets waved in. The same user appearing from a country where you have no staff gets stopped.
If your facilities are in Oklahoma, Texas and Arkansas, there is rarely a reason for a sign-in from overseas. A location-based rule that blocks countries outside your footprint removes a large share of automated attacks. Create exceptions for staff who travel, and review them regularly.
Make MFA the default for all users and all cloud applications, then carve out narrow exceptions only where you must. Pay special attention to administrator accounts, which should always require MFA and should be separate from daily-use accounts.
Older email protocols cannot perform MFA, so attackers target them to bypass it. Unless you have a specific old device or scanner that depends on one, block legacy authentication entirely. This single rule closes a door that many password-spray attacks rely on.
For applications that hold resident or patient information, you can require that the device be managed and meet basic standards, such as an encrypted disk and a supported operating system. Personal phones and unknown computers can still reach email on the web, perhaps with limited functions, but not download files.
Higher license tiers include risk detection that flags impossible travel, anonymous proxies and known-leaked credentials. You can require a password change or a fresh MFA prompt when risk is elevated. If your licensing includes it, this is one of the highest-value settings available.
The reason many organizations hesitate is fear of lockouts and constant prompts. A few practices keep the experience smooth:
Start in report-only mode. Microsoft 365 lets you test a policy and see who would have been affected before you enforce it.
Pilot with a small group. Try IT staff and one friendly department first.
Keep a break-glass account. Maintain one or two emergency administrator accounts excluded from the rules, protected with very long passwords and monitored for any use.
Reduce prompts for trusted situations. Allow longer sessions on managed devices in your facility, and ask for MFA more often on unfamiliar ones.
Communicate in plain language. Tell staff what is changing and why in two or three sentences, and give them one number to call.
Senior-living and nursing environments have realities that office-style policies ignore. Staff may share workstations, work overnight, or use a personal phone for authentication. Plan for these cases explicitly. Shared workstations may need different rules than personal laptops, and staff without smartphones may need a hardware key or another approved method. A policy that ignores the floor will be bypassed.
Conditional Access is not a set-and-forget project. Review the sign-in logs monthly for blocked attempts and for legitimate users caught by mistake. Update your allowed-country list when a new site opens or an executive travels. Document each policy in plain language so that a new administrator understands why it exists.
Healthcare regulators expect reasonable safeguards for access to electronic protected health information under the HIPAA Security Rule. Context-aware sign-in rules are a practical way to show that you have thought about who can reach your systems and under what conditions.
UnityCare IT helps healthcare and senior-living operators design these policies, test them in report-only mode, and roll them out with minimal disruption to staff. If your Microsoft 365 tenant has never had its sign-in rules reviewed, that review is a good place to begin.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172