Identity Verification In the Digital World | Blog | Vouched

NIST No Longer Permits Knowledge-Based Verification. Here’s What Health Systems Should Do Next

Written by Vouched Team | Sep 15, 2026, 10:50:43 PM

On July 31, 2025, NIST published revision 4 of its identity proofing guidelines, SP 800-63A. The update carries one requirement that changes how health systems verify patients and providers: knowledge-based verification (KBV) “shall not be used for identity verification.”

The earlier version allowed knowledge-based verification at IAL2 under certain conditions: four questions, limited attempts, timed responses. Revision 4 removes it as a way to prove identity. Credential service providers can still use these checks inside a fraud program. They can no longer use them to confirm who someone is.

If your patient portal enrollment, medical records requests, proxy access, provider onboarding, or call center scripts still rely on out-of-wallet questions from a credit bureau, they no longer meet the standard.

Where knowledge-based verification still sits

Many health systems run several identity-proofing processes at once, and ownership is spread across many employees. Before you can get rid of knowledge-based verification, you have to find it first, like:

  • Portal self-enrollment and account recovery
  • Release-of-information and HIPAA right-of-access requests
  • Proxy and caregiver access
  • Provider and workforce onboarding
  • EPCS enrollment for prescribers

The most common and least documented is the call center. An agent who asks a caller to confirm date of birth, address, and the last four digits of a Social Security number is performing knowledge-based verification. A person on the phone doesn’t change what it is.

Why NIST removed it

The case against knowledge-based verification is simple: the answers aren’t a secret. The method assumes a fact is known only to the person and an authoritative source. That method may have held up in 2005, but it doesn’t anymore. The Change Healthcare attack alone exposed the records of about 190 million people, the largest breach of health data on record, and it included the categories of data these questions depend on. Add years of prior breaches and the data-broker market, where past addresses and lenders sell for a few dollars, and the model stops working. You end up asking an attacker to prove they can look something up.

Knowledge-based verification also relies on a credit file. Patients with thin or no credit history fail. So do recent immigrants, young adults, people who move often, and elderly patients who can’t recall an auto loan from 14 years ago. 

Each failure becomes a help-desk call, a trip to the records office, or a patient who gives up on reaching their own health information. Under HIPAA, verification can’t create unreasonable barriers to a person’s right of access. A method that rejects legitimate patients at a high rate, with the effect concentrated among vulnerable groups, poses a right-of-access and information-blocking risk.

Why this reaches you even though you’re not a federal agency

NIST guidance binds federal agencies, and your health system isn’t one. It still reaches you through your contracts. Under TEFCA, Individual Access Services providers must verify individuals to IAL2 through an approved credential service provider, and the approval process references the latest version of SP 800-63A. When NIST published revision 4, the definition of IAL2 that TEFCA relies on also changed. There’s no grandfather clause. If your service — or your vendor’s - still runs knowledge-based verification as a verification step, it no longer meets the standard it claims to meet.

What to build instead

Revision 4 names three ways to reach IAL2, and you can use more than one:

  • No biometrics. You don’t need face matching at all. Mail a code to a validated postal address, or have a trained agent compare the applicant to the photo on their ID. It’s a good fit when face recognition worries your patients or your board.

  • Biometrics. Match a live selfie to the photo on the ID. Most "selfie plus ID" vendors already do this. If you choose it, check your state’s biometric-privacy laws and ask your vendor how their matching performs across demographics.

  • Digital credentials. Accept mobile driver’s licenses and other verifiable credentials. Adoption is still early, but this is where the market is heading.

 

Hospitals have an advantage they need to use

Revision 4 allows IAL2 proofing in person and remotely. You have registration desks, records offices, and pharmacies. A patient who fails document capture on their phone still has a way through. They make a five-minute stop at the front desk, where a trained agent compares them to their driver’s license. 

Revision 4 also defines trusted referees, who can make risk-based decisions when an applicant can’t meet standard requirements, and applicant references, who can vouch for someone’s identity or circumstances. If you serve a safety-net population, build these roles on purpose.

 

The bottom line

Knowledge-based verification was a weak control before July 2025. Now, it’s also a nonconforming one. Find out where it still runs, set a date to remove it, and create at least two pathways so no patient depends on a single method. The security questions your patients answer today already sit in a breach file somewhere, and the patients who fail them are often the ones who have the hardest time getting care.

This post is general information about a technical standard, not legal advice. Confirm your obligations with your compliance and privacy counsel.