Stolen passwords are one of the most common ways attackers get into email, remote access tools and cloud applications. Multi-factor authentication, or MFA, adds a second proof of identity so that a password alone is not enough. Most administrators agree it is a good idea. The hesitation is usually practical: staff share workstations, hands are full, phones may not be allowed on the floor, and nobody wants to slow down medication passes.
A phased plan solves most of these concerns. Start where the risk is highest and the friction is lowest, then work toward the harder cases.
Begin with accounts that give broad access or can be reached from the internet:
Administrator and IT accounts, without exception
Email, especially for executives, billing and HR
Remote access such as VPN or remote desktop
Cloud applications that store resident or employee data
Any vendor portal that touches banking or payroll
This phase mainly affects office staff and managers, who are generally comfortable with a phone prompt. It also addresses the scenarios most likely to lead to serious loss.
Not every MFA method is equal, and not every one suits every role.
Authenticator app prompts are a solid default for staff with smartphones
Hardware security keys work well for administrators and shared environments
Text message codes are better than nothing, but are weaker against some attacks, so treat them as a fallback
Number-matching prompts reduce the risk of people approving a request by reflex
Plan for people without a work-approved phone. Offering a hardware token or key means you do not force personal devices on staff who would rather not use them.
This is where rollouts often stall. A nurse who logs in to a station fifteen times per shift will not tolerate a prompt each time.
Use badge tap or proximity-card sign-in for workstation access where possible
Set sensible session lengths so that re-authentication happens at shift boundaries rather than every few minutes
Apply stronger checks to risky events, such as sign-in from a new location, rather than every login
Make sure screen lock and automatic logoff are configured so that sessions do not stay open at empty stations
Your EHR vendor, such as PointClickCare or another platform, may have its own options for authentication. Ask what is supported before you design anything custom.
Staff accept changes that are explained. Send a short note covering why you are doing this, what will change, and who to call for help. Then hold brief hands-on sessions at shift changes so that people enroll with someone beside them.
Provide a one-page enrollment guide with screenshots
Offer drop-in help for the first week at each site
Tell staff that IT will never ask them to read out a code
Explain what to do if they receive a prompt they did not trigger: deny it and report it
Unexpected prompts are a warning sign that someone has the password. Staff who understand this become part of your detection.
The helpdesk process matters as much as the technology. Decide in advance how identity is verified before resetting MFA, because attackers will try to talk support staff into resetting it.
Verify through a manager or a known phone number, not just a name and employee number
Keep a record of every reset
Have a temporary access method for emergencies such as a new phone on a weekend
Remove devices from the account when employees leave
After the first phases, review which accounts still rely only on a password. Look at service accounts, shared mailboxes, older applications and legacy systems. Some will not support MFA, and those need compensating controls such as network restrictions and closer monitoring.
It is also worth recording your MFA coverage in your HIPAA risk analysis, since access control and authentication are central to protecting electronic patient information.
UnityCare IT helps healthcare and senior-living operators plan MFA rollouts that account for shared stations, shift work and EHR compatibility. If you are unsure which accounts are covered today, we can run an inventory and suggest a sequence that fits your staffing and budget.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172