Use passwordless options, risk-based MFA, and consistent recovery flows so legitimate users can authenticate without repeated friction. The goal is to narrow attack opportunity while keeping login and prescription refill journeys usable. PBMs should also monitor for credential stuffing patterns, because high-value member portals remain attractive targets for takeover attempts.
Why This Matters for Security Teams
For PBMs, account takeover is not just a login problem. Member portals touch prescriptions, personal data, and downstream fulfillment workflows, so a single compromised account can create fraud, privacy, and service disruption at the same time. The hard part is reducing attacker success without turning every refill, update, or support interaction into a friction-heavy verification event. Current guidance from NIST Cybersecurity Framework 2.0 and the OWASP Non-Human Identity Top 10 both point toward stronger authentication and better risk decisions, but PBMs have to operationalise that without harming member access.
NHI Management Group’s research shows why this matters operationally: the Ultimate Guide to NHIs reports that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, a reminder that identity abuse often extends far beyond the member login itself. In practice, many security teams encounter takeover patterns only after fraud, support tickets, or refill abuse have already begun, rather than through intentional detection.
How It Works in Practice
The best balance starts with reducing password dependence. Passwordless authentication, phishing-resistant MFA, and device-bound authenticators make it harder for credential stuffing and replay attacks to succeed, while risk-based step-up checks keep low-risk journeys fast. For PBMs, that means a routine login from a known device may require little or no extra friction, while a risky session from a new location, an unusual refill pattern, or a high-velocity request triggers stronger verification.
That control model works best when recovery is just as disciplined as sign-in. Many account takeovers succeed through weak reset flows, so password reset, account recovery, and support-assisted identity proofing should follow the same assurance standard as primary authentication. Members should not face different rules depending on whether they are logging in on their own or being helped by support. Consistent recovery flows also reduce the attacker’s ability to exploit gaps between digital and call-centre processes.
Practitioners should also treat session and anomaly telemetry as first-class controls. Watch for impossible travel, repeated failed attempts, reused credentials across many accounts, changes to contact details immediately before refill actions, and automation signatures that resemble bot-driven stuffing. For deeper governance patterns, the Ultimate Guide to NHIs — Key Challenges and Risks is useful because it shows how identity sprawl and weak lifecycle control amplify abuse across environments, not just at the login screen. These controls tend to break down when legacy portals, third-party call centres, and mail-order workflows rely on different identity proofing standards because attackers target the weakest recovery path.
Common Variations and Edge Cases
Tighter authentication often increases support load and can slow urgent member actions, so organisations have to balance fraud reduction against access to care. That tradeoff is especially visible in low-bandwidth environments, older member populations, and delegated-access scenarios where a caregiver or family member may legitimately act on behalf of the member.
Current guidance suggests using step-up authentication only when risk justifies it, but there is no universal standard for exactly which signals should trigger friction. Some PBMs will prioritise device reputation and IP intelligence, while others may lean more heavily on behavioural patterns or transaction context. The key is to keep the member journey predictable: the same recovery path, the same escalation criteria, and the same support handoff rules across channels.
PBMs should also be careful not to overfit controls to password stuffing alone. Account takeover can start with social engineering, compromised email, SIM swap, or support abuse, so a narrow fix creates a false sense of security. The operational question is not whether to add friction, but where to place it so attackers feel it first and members feel it last.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A1 | Phishing-resistant auth and step-up checks reduce takeover exposure. |
| OWASP Non-Human Identity Top 10 | NHI-06 | Identity lifecycle and recovery controls limit abuse of accounts and sessions. |
| CSA MAESTRO | IAM-01 | Identity assurance for agentic workflows maps to secure access decisions. |
| NIST CSF 2.0 | PR.AA-01 | Authentication strength and account recovery directly affect access risk. |
| NIST AI RMF | GOVERN | Risk-based decisions and accountability align with AI-assisted detection and access. |
Govern risk-scored authentication decisions and review their outcomes for fairness and safety.
Related resources from NHI Mgmt Group
- How should security teams reduce account recovery risk without making sign-in harder?
- How should banks reduce account takeover risk without making login unusable?
- How can organisations reduce account takeover risk without hurting user experience?
- How should retailers reduce login friction without increasing account takeover risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org