The short answer: MFA is essential and non-negotiable — it kills password-reuse and password-spray attacks outright. But modern phishing kits steal the session after you approve the MFA prompt, “MFA fatigue” attacks push prompts until someone taps approve, and a compromised vendor with legitimate remote access never sees an MFA screen at all. MFA is one lock on one door of a building with several doors.
What MFA genuinely stops
Credit where due: the majority of small-practice compromises historically started with a reused or leaked password. MFA slams that door. If any account in your practice — email, practice management, remote access, banking — still runs on password alone, stop reading and fix that first. It’s included in every Phoenix security stack for a reason.
The attacks that walk past it
- Session token theft. Current phishing kits proxy the real login page: the victim enters their password, approves the genuine MFA prompt, and the kit captures the resulting session cookie — the browser’s “already signed in” pass. The attacker replays it and is in, MFA satisfied.
- MFA fatigue. Attackers with a stolen password trigger prompt after prompt at 11 PM until an exhausted employee approves one to make it stop. It works depressingly often.
- Compromised vendors. Your imaging vendor’s remote tool, your old IT provider’s leftover access, the billing service’s VPN — legitimate channels that inherit whatever security the vendor has. Attacks through vendor access never touch your MFA.
- Malware on the endpoint. Once a machine is compromised — a malicious attachment, a poisoned download — the attacker operates inside sessions that are already authenticated.
What “layered” means in practice
Each layer catches what the previous one misses: filtered email so fewer phishing links arrive; trained staff so fewer get clicked; conditional access so a stolen token from an unknown device gets challenged anyway; endpoint detection and response so malware that lands is spotted by behavior and the machine is isolated in minutes; monitored vendor access so third-party channels are inventoried and watched; and immutable backups so the worst case is a bad day instead of a closed practice. That last-plus-first combination — not any single product — is why our clients have never paid a ransom.
For the full stack — detection and response, identity, email, training, and recovery — see healthcare cybersecurity services, or keep the first-hour ransomware guide where your office manager can find it.