Multi-factor authentication, usually shortened to MFA, asks a user to prove who they are with more than a password. It might be a code from an app, a prompt on a phone, a security key or a badge. Government agencies including CISA strongly recommend it, and cyber insurance applications often ask whether it is in place. Yet many care organizations hesitate. The reasons are usually understandable, and most rest on myths.
Reality: MFA can be designed to stay out of the way. Prompts do not need to appear on every action. Many systems remember a trusted device for a period of time, or only ask when something unusual happens, such as a sign-in from a new location. Prioritize the places where MFA matters most first: email, remote access, administrator accounts and cloud applications. Shared nursing workstations often need a different approach, such as badge tap, rather than phone prompts.
Reality: Strong passwords still get stolen through phishing, reused passwords from other breaches and malware. Attackers do not need to guess a password if they can trick a person into typing it into a fake page. With MFA enabled, a stolen password alone is generally not enough to get in.
Reality: There are options beyond smartphone apps:
Hardware security keys that plug into a computer or tap on a reader
Physical tokens that display a code
Proximity badges combined with a PIN
Phone call or text codes as a fallback, though these are weaker than app or key methods
If you ask staff to use personal phones, discuss privacy concerns openly, make sure no personal data is collected by the app and consider offering a facility-provided alternative.
Reality: Methods vary in strength. Text message codes are better than nothing but can be intercepted through techniques such as SIM swapping. Attackers also try prompt bombing, sending repeated approval requests until a tired user taps accept. Stronger choices include app prompts that require entering a displayed number and phishing-resistant methods such as security keys or passkeys. A practical approach is to start with what staff will actually use, then move higher-risk accounts to stronger methods.
Reality: Many tools you already own include MFA. Microsoft 365 and Google Workspace both offer it, and many EHR and remote access products support it too. The cost is often more in planning and training than in licenses. A phased rollout, starting with administrators and email, spreads the effort.
Administrator and privileged accounts. These are the keys to everything.
Email. A compromised mailbox leads to fraud and further breaches.
Remote access, such as VPN and remote desktop.
Cloud applications that hold resident or financial data.
EHR and clinical systems, where supported and workable on the floor.
Everything else, over time.
Pilot with a small group. Start with leadership and office staff to uncover issues.
Communicate early. Explain why, what staff will see and who to call.
Provide hands-on enrollment help. Hold short sessions on each shift.
Plan for lost phones and new hires. Document how to reset or enroll a device and verify identity before doing so.
Keep emergency access. Maintain a small number of secured break-glass accounts so you are not locked out during an outage.
Avoid exceptions that become permanent. Track and review any account excluded from MFA.
MFA greatly reduces risk but does not replace patching, backups, staff training or monitoring. HIPAA's Security Rule calls for person or entity authentication, and MFA is a strong way to meet that expectation, but it works best as part of layered protection.
Make a list of every system that holds resident information or lets people connect remotely, and mark which ones require more than a password today. The unchecked ones become your rollout plan.
UnityCare IT helps healthcare organizations turn on and manage MFA in ways that fit care workflows, from email and remote access to shared workstation sign-in. If you would like to talk through options, we are happy to help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034