High-risk login controls for a healthtech account must use device fingerprints as signals, preserve event reporting for audit, and require step-up verification before an irreversible GDPR deletion, without turning every ordinary login into an obstacle course.

Short answer: treat device fingerprints as signals, event reports as auditable facts, and risk scores as inputs to a policy that requires step-up verification for account deletion and other high-risk actions while leaving low-risk activity alone.

The score is not identity. It can decide which proof to request; it must never become the proof itself.

What should high-risk login controls do with device fingerprints, event reporting, and step-up verification?

Start with the action, not the vendor. A familiar device signing in to view a dashboard and an unfamiliar device requesting account deletion should not cross the same boundary. The first path should preserve continuity. The second should require fresh evidence, because a stolen session that can delete the account and erase access is materially different from one that can read an already-authorized page.