Passkeys Reduce Account‑Takeover Risk for HealthEquity and the Broader Healthcare Sector
What Happened — HealthEquity’s fraud leader, Ajit Gaddam, explained at Black Hat USA 2026 how the company is replacing passwords with device‑based passkeys. Passkeys store a private key on the user’s device and unlock it with biometrics, eliminating reusable passwords and the recovery workflows attackers often exploit.
Why It Matters for Compliance & Audit Readiness
- Credential‑based attacks are a primary failure point in SOC 2 CC6 (Logical Access) and CC7 (System Operations); passkeys directly address the control “Authentication mechanisms protect against unauthorized access.”
- Deploying passkeys provides continuous, cryptographic evidence of strong authentication, simplifying audit evidence collection for access‑control policies.
- The shift reduces reliance on recovery processes that are often under‑documented, helping organizations demonstrate “least‑privilege” and “identity assurance” in their SOC 2 audit.
Who Is Affected — Healthcare providers, health‑benefits platforms, and any SaaS firms handling protected health information (PHI).
Recommended Actions
- Map the “Password‑less authentication” control to SOC 2 CC6 and update your access‑control policy.
- Capture passkey enrollment logs as audit evidence and integrate them into your continuous‑compliance dashboard.
- Train support and call‑center staff on the new workflow to avoid social‑engineering gaps. Source: DataBreachToday
Technical Notes
- Attack vector mitigated: stolen credentials and recovery‑workflow abuse.
- No known CVE; the mitigation is a change in authentication architecture rather than a patch. Source: DataBreachToday