---
title: Duty of Care and Information Security
description: The Hippocratic oath and the principles embodied in “duty of care” guide healthcare providers – when it comes to data security, are they living up to them?
image: https://blog.strongkey.com/hubfs/Stock%20images/Science%20graphic%20against%20researcher%20hands%20holding%20sprouts%20in%20petri%20dish.jpeg
---

[![StrongKey Logo](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

INDUSTRY

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa50e587d1ab_cpu%20(1).svg) 

[Fintech Payments, card capture ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg)](https://www.strongkey.com/solutions/industry/fintech) [Enterprise Fully scalable customization ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg)](https://www.strongkey.com/solutions/industry/enterprise) [Manufacturing IIoT integration, key injection ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg)](https://www.strongkey.com/solutions/industry/manufacturing)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2d4787d1e0_check-square.svg)

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated; low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burden of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

Products

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

SOFTWARE

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa215487d1ca_activity.svg) 

[FIDO2 Passwordless Authentication Reduce password-related costs ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg)](https://www.strongkey.com/products/software/fido-strong-authentication) [Public Key Infrastructure Build new or update existing ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg)](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [Encryption & Tokenization For small and mid-sized applications ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg)](https://www.strongkey.com/products/software/tokenization-and-encryption) [Custom Solutions Work with us to find a solution ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cffdbccd1c7f01ee3fce_cicruit.svg)](https://www.strongkey.com/products/software/custom-solutions)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa92287d205_truck.svg)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Development Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy and future](https://www.strongkey.com/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) Partners and Resellers Who we do business with](https://blog.strongkey.com/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/careers)

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) 

[DEMOS ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa61e187d118_arrow-left.svg)](https://www.strongkey.com/demos)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated for low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burdens of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

INDUSTRY

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg) Fintech Payments, card capture](https://www.strongkey.com/solutions/industry/fintech) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg) Enterprise Fully scalable customization](https://www.strongkey.com/solutions/industry/enterprise) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg) Manufacturing IIoT integration, key injection](https://www.strongkey.com/solutions/industry/manufacturing)

Products

SOFTWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg) FIDO Passwordless Authentication Reduce password-related costs](https://www.strongkey.com/products/software/fido-strong-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg) Public Key Infrastructure Build new or update existing](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg) Encryption & Tokenization For enterprise applications](https://www.strongkey.com/products/software/tokenization-and-encryption)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Collaboration Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy, and future](https://www.strongkey.com/about/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/about/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/about/careers) 

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) [Demos](https://www.strongkey.com/demos)

[Arshad Noor](https://blog.strongkey.com/blog/author/arshad-noor) - Mar 26, 2019

# Duty of Care and Information Security

- [Tweet](https://twitter.com/share)

[FIDO](https://blog.strongkey.com/blog/tag/fido)  [Healthcare](https://blog.strongkey.com/blog/tag/healthcare)  [Encryption/Tokenization](https://blog.strongkey.com/blog/tag/encryption-tokenization)

The Hippocratic oath and the principles embodied in [“duty of care” ](http://www.rotlaw.com/legal-library/what-is-a-duty-of-care/)guide the daily actions of healthcare providers. But when it comes to information security and protecting sensitive PHI, is the healthcare community living up to those principles?

#### **What’s at Stake**

The healthcare industry has had its share of large data breaches despite being regulated in the U.S. by the Centers for Medicare & Medicaid Services and federal law – the Health Insurance Portability & Accountability Act (HIPAA) – which mandate the security and privacy of sensitive healthcare data. So, it’s not a lack of cybersecurity guidelines that has led to ongoing data security and privacy incidents.

Given that patient data is deemed of the highest valuable by attackers on the dark web, healthcare providers are reminded that besides a professional and ethical responsibility to patients, they also have a fiduciary responsibility in protecting patient data, since a failure of this responsibility can endanger the health of their patient due to avoidable stresses caused by the breach of their PII and PHI.

Medical professionals have always had an ethical obligation to the first rule in healthcare – “do no harm” – and a responsibility to care for the patient’s health first. With the age of digital transformation in the healthcare field, better patient care backed by streamlined data and operations is available. While these technologies improve patient outcomes and lower costs, they come with compliance and security risks.

Healthcare organizations that handle PHI can’t afford to fall victim to cyberattacks. A breach has the potential to not only affect patient care and the trustworthiness of the healthcare organization but can go so far as to endanger the patient’s life if the integrity of data produced by medical equipment or records cannot be trusted. Consequently, it is vital that healthcare professionals understand the value of the data they have access to.

#### **Primary Causes of a Data Breach**

In the world of cloud-based file-sharing schemes, it would seem that a healthcare provider using encryption to protect their patients’ data in the cloud might satisfy the “duty of care” principle. But, as someone who has spent nearly two decades in the field of encryption, I would argue that the cloud service provider that has control over encryption keys can decrypt those encrypted documents at any time.

To make matters worse, healthcare applications that use passwords to authenticate patients and healthcare professionals to web applications are using the oldest and weakest authentication technology on the planet to protect access to information when stronger ones are available – sometimes at little or no cost to the healthcare provider who owns the application.

When you combine these two weak control mechanisms, you have a situation that allows confidential information to be breached by attackers, and neither the healthcare professional nor their patient may be aware that the information has been breached. In many cases, until the news breaks to the public, the healthcare providers do not often know they’ve been breached.

In such a situation, one can argue that the healthcare providers have failed in their duty by not employing readily available tools and mechanisms that have significantly higher probability of protecting their patients’ information.

#### **Defending the Wrong Territory**

Where healthcare organizations get it wrong is in assuming that network security tools are sufficient. Much as the Department of Transportation cannot prevent accidental traffic deaths by spending more on monitoring systems for its network of highways, spending more money on IT network security is a waste of money. The focus should be on protecting the sensitive data itself.

Most data breaches occur because of the mistaken notion that it is easier to deter “barbarians at the gate” rather than actually protect sensitive data in the application. As a result, hospitals over-invest in network-based security tools – firewalls, anti-virus, malware detection, intrusion prevention, etc. – rather than invest in the control mechanisms that provide the highest level of data protection.

#### **Security Controls for Better Protection of Patient Data**

Here are necessary security precautions healthcare organizations can take to protect the confidentiality of patients’ information:

- Eliminate any form of shared-secret authentication scheme being used to authenticate humans to applications. Adopt the FIDO Alliance’s [WebAuthn ](https://fidoalliance.org/fido-alliance-and-w3c-achieve-major-standards-milestone-in-global-effort-towards-simpler-stronger-authentication-on-the-web/)as the authentication standard and do not delegate the authentication to a third-party Identity Provider. New privacy laws such as the General Data Protection Regulation and California Consumer Privacy Act create new liabilities for healthcare providers if the Business Associate Agreement (BAA) does not protect the healthcare provider.
- Encrypt data at the source where information is captured – at the application level. This is the surest long-term method for protecting sensitive data because the application layer is the highest layer in the technology stack. This makes it the most logical place to protect data, since it offers the attacker the smallest target. In addition, once data leaves the application layer, it is protected no matter where it goes – and it must return there to be decrypted.
- Preserve the integrity of data stored within electronic health records and databases.

#### Data Security is Patient Care

Today, duty of care for healthcare organizations includes keeping patients’ sensitive data secure and private. However, relying on weak authentication practices and network security tools to do the job is a recipe for data breaches. Cybercriminals are eager for health data, so the healthcare industry must step up its data security efforts to offer the highest level of data care, just as they strive to provide the highest level of patient care. Use the guidelines above to ensure patient data receives the strongest protection possible.

#### About the Author:

Arshad Noor is the CTO of StrongKey, a Silicon Valley and Durham, NC based company focused on securing data through key management, strong authentication, encryption and digital signatures. He has 32 years of experience in the Information Technology sector, of which, more than 19 were devoted to designing and building key-management infrastructures for dozens of mission-critical environments around the world. He has been published in periodicals and journals, as well as authored XML-based protocols for two Technical Committees at OASIS and represents StrongKey at the FIDO Alliance. He is also a frequent speaker at forums such as RSA, ISACA, OWASP and the ISSE. He can be reached at [arshad.noor@strongkey.com](mailto:arshad.noor@strongkey.com).

**ALSO SEEN IN: [Becker's Health IT](https://www.beckershospitalreview.com/cybersecurity/duty-of-care-and-information-security.html)**

### ALL TOPICS

- [FIDO (45)](https://blog.strongkey.com/blog/tag/fido)
- [Culture/Influence (31)](https://blog.strongkey.com/blog/tag/culture-influence)
- [Cybersecurity ROI (29)](https://blog.strongkey.com/blog/tag/cybersecurity-roi)
- [Breaches (16)](https://blog.strongkey.com/blog/tag/breaches)
- [Encryption/Tokenization (16)](https://blog.strongkey.com/blog/tag/encryption-tokenization)
- [Payments/E-Commerce (15)](https://blog.strongkey.com/blog/tag/payments-e-commerce)
- [Disruptive Defenses (14)](https://blog.strongkey.com/blog/tag/disruptive-defenses)
- [Key Management (11)](https://blog.strongkey.com/blog/tag/key-management)
- [PSD2 (11)](https://blog.strongkey.com/blog/tag/psd2)
- [GDPR and CCPA (8)](https://blog.strongkey.com/blog/tag/gdpr-and-ccpa)
- [SCA (8)](https://blog.strongkey.com/blog/tag/sca)
- [Events (7)](https://blog.strongkey.com/blog/tag/events)
- [Employee Spotlight (6)](https://blog.strongkey.com/blog/tag/employee-spotlight)
- [Ransomware (5)](https://blog.strongkey.com/blog/tag/ransomware)
- [COVID-19 (4)](https://blog.strongkey.com/blog/tag/covid-19)
- [PCI DSS (4)](https://blog.strongkey.com/blog/tag/pci-dss)
- [Products (4)](https://blog.strongkey.com/blog/tag/products)
- [Blockchain (3)](https://blog.strongkey.com/blog/tag/blockchain)
- [Healthcare (3)](https://blog.strongkey.com/blog/tag/healthcare)
- [Hybrid Cloud (RC3) (3)](https://blog.strongkey.com/blog/tag/hybrid-cloud-rc3)
- [IoT (3)](https://blog.strongkey.com/blog/tag/iot)
- [PKI (3)](https://blog.strongkey.com/blog/tag/pki)
- [Press Releases (2)](https://blog.strongkey.com/blog/tag/press-releases)
- [Citrix (1)](https://blog.strongkey.com/blog/tag/citrix)
- [Passkeys (1)](https://blog.strongkey.com/blog/tag/passkeys)

### Most Popular

<https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Key Management](https://blog.strongkey.com/blog/tag/key-management) [Passkeys](https://blog.strongkey.com/blog/tag/passkeys)

**[“Would you trust your bank with both keys to your ....](https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box)**

<https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses)

**[An In-depth Guide to FIDO Protocols: U2F, UAF, and....](https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2)**

<https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how>

[Key Management](https://blog.strongkey.com/blog/tag/key-management) [Cybersecurity ROI](https://blog.strongkey.com/blog/tag/cybersecurity-roi)

**[Key Custodians: Who, What, Where, When, Why, and H....](https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how)**

<https://blog.strongkey.com/blog/fido-101-strong-authentication>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses) [Culture/Influence](https://blog.strongkey.com/blog/tag/culture-influence)

**[FIDO 101: Understanding FIDO Strong Authentication....](https://blog.strongkey.com/blog/fido-101-strong-authentication)**

### Archive

- [March 2026 (1)](https://blog.strongkey.com/newsroom/archive/2026/03)
- [June 2025 (1)](https://blog.strongkey.com/newsroom/archive/2025/06)
- [March 2022 (1)](https://blog.strongkey.com/newsroom/archive/2022/03)
- [December 2021 (1)](https://blog.strongkey.com/newsroom/archive/2021/12)
- [March 2021 (6)](https://blog.strongkey.com/newsroom/archive/2021/03)
- [December 2020 (4)](https://blog.strongkey.com/newsroom/archive/2020/12)
- [November 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/11)
- [October 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/10)
- [September 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/09)
- [August 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/08)
- [June 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/06)
- [April 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/04)
- [February 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/02)
- [January 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/01)
- [December 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/12)
- [September 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/09)
- [August 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/08)
- [July 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/07)
- [June 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/06)
- [May 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/05)
- [April 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/04)
- [March 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/03)
- [February 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/02)
- [January 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/01)
- [December 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/12)
- [November 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/11)
- [October 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/10)
- [September 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/09)
- [August 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/08)
- [July 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/07)
- [April 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/04)
- [January 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/01)
- [October 2017 (1)](https://blog.strongkey.com/newsroom/archive/2017/10)

![Strongkey - Logo](https://blog.strongkey.com/hubfs/Strongkey%20-%20Logo.png "Strongkey - Logo")

StrongKey provides solutions to companies looking to solve for PCI DSS, PSD2 Strong Customer Authentication, passwordless authentication with FIDO, data privacy, public key infrastructure and other security challenges.

Copyright 2022 StrongKey, Inc.

- [Privacy Policy](https://www.strongkey.com/about/privacy-policy)
- [Terms of Use](https://www.strongkey.com/about/terms-of-use)
- [Cookie Policy](https://www.strongkey.com/about/cookie-policy)

#### About

- [Company](https://www.strongkey.com/about/company)
- [Newsroom](https://blog.strongkey.com/newsroom)
- [Events](https://www.strongkey.com/about/events)
- [Careers](https://www.strongkey.com/about/careers)

#### Solutions

- [PCI DSS](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services)
- [FIDO](https://www.strongkey.com/products/software/fido-strong-authentication)
- [PSD2 SCA](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication)
- [CCPA](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)
- [GDPR](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2)
- [NACHA](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection)

#### Resources

- [Library](https://blog.strongkey.com/resources)
- [CONTACT US](https://www.strongkey.com/contact)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526cad36f3a5e723525fba_GitHub_logo_white_10%25.png)](https://github.com/StrongKey) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa071787d2c3_Twitter.png)](https://twitter.com/strongkeyinc) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa775287d2c0_Linkedin.png)](https://www.linkedin.com/company/strongkey)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526bcf0df80d185f961b8d_youtube_white_icon.png)](https://www.youtube.com/channel/UCueU61oRt9G6MILRSHIfimA) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036be2bdf2d65e2d2fc906f_Instagram_5%25.png)](https://www.instagram.com/strongkeyinc/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036bd8ef3da6a4bb2e24382_facebook_10%25.png)](https://www.facebook.com/strongkeyinc/)

#### Subscribe to Our Newsletter

Receive helpful information and the latest news from the world of cybersecurity