YubiKey in Healthcare and Law Firms: Why Basic Authentication is Not Enough
Share
The AEPD registered 93 security breach notifications in the healthcare sector between 2024 and April 2026, the second most affected sector in Spain after tourism (AEPD, notifications dashboard). In law firms the problem is different but equally real: a single misdirected email is enough to leak client data protected by attorney-client privilege.
Healthcare and legal services share something that makes them priority targets: they manage highly sensitive third-party data, with regulatory obligation to protect it. An access failure is not just a technical problem — it is a direct legal responsibility.
Healthcare: clinical records under GDPR Article 9
Health data is classified as a special category under GDPR Article 9. Its processing is restricted to specific exceptions, and a breach exposing it carries more severe penalties than ordinary personal data — the AEPD can impose fines up to 20 million euros or 4% of global turnover.
Unauthorized access to a clinical record is not a remote scenario. With 93 notifications in the analyzed period, the Spanish healthcare sector concentrates a significant portion of incidents reported to the AEPD. Exposure does not depend solely on the size of the facility — a small clinic with password-shared access is just as exposed as a large hospital.
It is usually not a sophisticated attack. It is a reused password, shared by email or intercepted by phishing — the most common entry point to systems with clinical data.
Legal: attorney-client privilege and client files
Attorney-client privilege obligates any law firm to protect client information with the same rigor demanded by the GDPR. The AEPD has already sanctioned cases that are anything but sophisticated: a law firm in Girona received a 10,000€ fine for sending an email without blind copy to eight recipients, exposing their personal data to each other.
You don't need a cyberattack to expose a client file. A shared access, an account without a second factor, or a misconfigured email is enough. The consequence is the same: the firm's liability to the client and to the AEPD.
Why 2FA via SMS or app is not enough here
SMS codes or authentication app codes (TOTP) can be intercepted with real-time phishing — the attacker creates a fake page, captures the code at the moment, and uses it before it expires. It is the most common unauthorized access method today.
A YubiKey based on the FIDO2 protocol eliminates that gap. Authentication is tied to the real domain of the service — a fake page cannot complete the process, even if the user falls for the trick. It is not an additional layer of friction: it is a different type of protection.
How to implement YubiKey in healthcare and law firms
Electronic health record, corporate email, document manager or case management platform — start with what gives access to third-party data.
Most modern health record and legal management platforms already support FIDO2. Check with your software provider before buying.
Registration takes minutes per user. It is recommended to have a backup key registered from day one, in case the primary key is lost.
A key without protection scratches and gets lost with daily use. Cases or card-type trays reduce that risk without adding bulk.
Compatible models
Holdtag accessories are compatible with these 4 models, verified:
| Model | Compatible |
|---|---|
| YubiKey 5 NFC | ✅ Yes |
| YubiKey 5C NFC | ✅ Yes |
| Security Key NFC | ✅ Yes |
| Security Key C NFC | ✅ Yes |
Accessories for daily use in clinical or law office settings
Manufactured in Spain (EU). NFC works without removing the key from the case or tray.
YubiKey Tray — 2 Slots
Credit card format, fits any wallet. Ideal for carrying main key + backup, as recommended in step 3.
Keychain with Lanyard
Protection against impact and scratches from daily use in clinic or office. Compatible with NFC without removing the key.
Is it worth it for your facility or firm?
If you manage clinical records or client files, yes — the cost of a key is minimal compared to real exposure to the AEPD. For a solo practice without access to especially sensitive data, a password manager with 2FA via app may be sufficient to start with.
It does not replace a complete security policy — it is one piece, not the entire solution.
Frequently asked questions
Is it legally mandatory to use YubiKey in healthcare or law firms?
There is no law that specifically requires YubiKey. The GDPR requires security measures "appropriate to the risk" — strong authentication against phishing is one way to meet that requirement, not the only one.
Does it work for multiple users in the same facility or firm?
Yes. Each person needs their own key registered on their account — it is not a key shared across the team.
What happens if the key is lost?
That is why it is recommended to register a backup key from the beginning (see step 3). Without a backup, recovering access depends on each platform's recovery process.
Does NFC work without removing the key from the case?
Yes, in Holdtag PLA+ cases and trays. In the threaded metal case (LL-Y03) NFC is blocked by the metal and requires removing the key.
YOU MAY BE INTERESTED IN
YubiKey for the public sector: security regulations in Europe
As an Amazon Associate, I earn from qualifying purchases.



