23 Jul Guarding the Gallery: Why Passkeys Are Replacing Texted Codes for Patient Image Security
Every practice that photographs and radiographs its patients is, whether it thinks of it this way or not, the keeper of a private gallery. Intraoral series, CBCT volumes, cosmetic before-and-afters — each is both a clinical record and an intimate portrait. The craft of capturing these images gets most of our attention. The craft of guarding them deserves just as much, and it is about to change in a way worth noticing: Microsoft is making passkeys the default way to sign in and retiring its texted and spoken verification codes on February 1, 2027.

The gallery behind the login
When a clinician opens a cloud mailbox, an imaging portal, or a shared drive, a single Microsoft account often stands between the outside world and a deep archive of patient images. That login is the gallery door. If it can be forced, everything inside — radiographs, photographs, the correspondence that accompanies them — is exposed. Protected health information is not only names and dates; a labeled radiograph is PHI in its own right, and a breach of it carries the same weight as any other.
For years the door has been guarded by a password plus a code sent to a phone. It was better than a password alone. It was never as strong as it looked.
Why the texted code was always a fragile lock
A verification code has to travel — across a cellular network, onto a screen, and then be typed back in. Everywhere it travels, it can be caught. A convincing fake sign-in page can ask for the code and pass it along in real time. An intercepted message can be replayed. And the phone number itself can be spirited away in a SIM-swap, where an attacker persuades a carrier to hand over the line. None of these require breaking encryption; they exploit the simple fact that a code is a secret in motion.

What a passkey changes
A passkey is a cryptographic credential bound to a device and unlocked by a fingerprint, a face, or a PIN. Nothing reusable ever crosses the network. There is no code to read aloud to a caller, nothing to type into a counterfeit page, no number to hijack. The secret stays on the device and proves itself without ever being exposed. For a gallery of patient images, that is the difference between a lock that can be picked from across the room and one that requires the key to be physically present.
This is why Microsoft is not merely offering passkeys but making them the default. From September 1, 2026, accounts still using SMS or voice will be enrolled in passkeys automatically and prompted to register one. From February 1, 2027, Microsoft-provided SMS and voice codes are retired outright. Practices that manage their own external telecom provider for messaging are unaffected; the change targets the built-in codes most offices quietly rely on.

Curatorship as security
There is a pleasing symmetry here. A good imaging practice already thinks like a curator: careful about how images are captured, catalogued, and presented. Access control is simply the same instinct extended to the vault. Registering a passkey for every clinician who touches patient images — and a backup passkey on a second device so no one is ever locked out — is the curatorial act of deciding, precisely and durably, who may enter the gallery.
The steps are unremarkable, which is the point: visit the account security page, add a passkey, confirm with a fingerprint or face scan, and repeat on a backup device. A minute of setup buys a far stronger lock on every sign-in that follows.

Future Developments
Passwordless access is not an endpoint but a direction. As passkeys become the default across the tools that hold clinical images, expect the same phishing-resistant logic to spread deeper into imaging itself — device-bound access to CBCT stations, hardware-key sign-in at shared operatory terminals, and portals that verify both the clinician and the integrity of the image they are viewing. The archive of the future will be one where a patient’s images are not only beautifully captured and faithfully preserved, but guarded by credentials that cannot be phished, replayed, or stolen. Tending that gallery — as science and as art — increasingly means tending the keys as carefully as the images themselves.
Sources & further reading:
- Microsoft Entra ID: Passkeys are the default authentication method (Microsoft Security Blog)
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication (Microsoft Learn)
No Comments