A Plain-English Guide to Multi-Factor Authentication for Care Teams

A stolen password is the easiest way into a care organization's systems. Staff reuse passwords, type them in front of others, and sometimes hand them to a phishing page that looks exactly like the email login screen. Multi-factor authentication (MFA) adds a second proof of identity, so a password alone is no longer enough to get in.

Many administrators and directors of nursing hear "MFA" and picture nurses fumbling with phones during a medication pass. That concern is fair, and it is solvable. This guide explains what MFA is, where to turn it on first, and how to roll it out in a way your staff will tolerate.

What MFA actually does

MFA asks for two or more different kinds of proof: something you know (a password), something you have (a phone, a key fob, a hardware security key), or something you are (a fingerprint or face scan). If an attacker has your password but not your phone, the login fails.

It does not make an account unbreakable. Attackers have learned to trick people into approving prompts they did not start. But MFA removes the cheapest and most common attack, and regulators and cyber insurance carriers increasingly expect to see it.

Where to turn it on first

Not every system needs the same urgency. Start where a compromise would hurt most:

Email and Microsoft 365 or Google Workspace accounts, since attackers use email to reset other passwords

Remote access, including VPNs, remote desktop and any vendor access path

Your EHR or EMR, such as PointClickCare, especially for administrator and billing roles

Banking, payroll and payment portals

Administrator accounts for your network, firewall, cloud and backup tools

Administrator accounts come first. One compromised admin account can undo every other safeguard you have.

Choosing the method

Not all second factors are equal. In rough order of strength:

Hardware security keys

Small USB or NFC keys that are very hard to phish. They are a good fit for administrators, executives and anyone with broad access.

Authenticator apps and push prompts with number matching

An app on a phone generates a code or sends a prompt. Number matching, where the user must type a number shown on the login screen, makes accidental approvals much less likely. This is the practical choice for most staff.

Text message codes

Better than nothing, but vulnerable to SIM swapping and interception. Use it only where nothing else is possible.

Handling the floor

Clinical staff on a busy hall are a different case from office staff. A few practical approaches help:

Use badge tap-in or fast user switching on shared workstations where your software supports it, so staff are not retyping long credentials all shift

Require MFA when logging in from outside the building or from a new device, and allow trusted facility devices to remember a login for a defined period

Give staff without personal smartphones a hardware key or a facility-provided option, and do not require them to install work apps on personal phones unless your policy covers that

Keep one or two approved backup methods so a dead phone does not stop a nurse from working

A simple rollout plan

Inventory the systems that hold resident or financial data and rank them by risk.

Turn on MFA for administrators and email first, within a week or two.

Pilot with a small group, such as the business office and one nursing unit, and note what slows people down.

Train staff with a short, concrete demonstration. Show what a real prompt looks like and what to do if one arrives unexpectedly.

Roll out to the rest of the organization in waves rather than all at once.

Set up a clear reset process, with identity verification, for lost or replaced phones.

Teach staff the one rule that matters

The most important training point is simple: if you did not just try to log in, never approve the prompt. Unexpected prompts are a sign that someone has your password. Staff should report them right away, and your IT provider should treat each report as a possible incident and reset the password.

Document it for HIPAA

The HIPAA Security Rule requires person or entity authentication and a risk analysis that considers your actual exposures. Turning on MFA, and writing down where and why you did, is the kind of reasonable and appropriate safeguard that supports both. Keep a short record of which systems are covered and the exceptions you approved.

Getting help

If you are not sure which of your systems support MFA, or how to roll it out without disrupting resident care, UnityCare IT can review your accounts and set it up in stages that fit your shifts. We work with long-term care and healthcare organizations across Oklahoma, Texas and Arkansas, and we are happy to start with a short assessment.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172