I’ve never seen or heard of 2FA being needed for BIOS access. However maybe we could consider “physical presence” as one type of factor, which does reduce the risk a lot.
Also, the article mentioned "partial passwords". I take that to mean the BIOS password was two parts, and only one part of the password was exposed.