Multi-Factor Authentication: Five Myths and the Realities

Multi-factor authentication, usually shortened to MFA, asks a user to prove who they are with more than a password. It might be a code from an app, a prompt on a phone, a security key or a badge. Government agencies including CISA strongly recommend it, and cyber insurance applications often ask whether it is in place. Yet many care organizations hesitate. The reasons are usually understandable, and most rest on myths.

Myth 1: Our staff are too busy for extra steps

Reality: MFA can be designed to stay out of the way. Prompts do not need to appear on every action. Many systems remember a trusted device for a period of time, or only ask when something unusual happens, such as a sign-in from a new location. Prioritize the places where MFA matters most first: email, remote access, administrator accounts and cloud applications. Shared nursing workstations often need a different approach, such as badge tap, rather than phone prompts.

Myth 2: Our passwords are strong, so we do not need it

Reality: Strong passwords still get stolen through phishing, reused passwords from other breaches and malware. Attackers do not need to guess a password if they can trick a person into typing it into a fake page. With MFA enabled, a stolen password alone is generally not enough to get in.

Myth 3: Staff will not have smartphones for it

Reality: There are options beyond smartphone apps:

Hardware security keys that plug into a computer or tap on a reader

Physical tokens that display a code

Proximity badges combined with a PIN

Phone call or text codes as a fallback, though these are weaker than app or key methods

If you ask staff to use personal phones, discuss privacy concerns openly, make sure no personal data is collected by the app and consider offering a facility-provided alternative.

Myth 4: All MFA is equally secure

Reality: Methods vary in strength. Text message codes are better than nothing but can be intercepted through techniques such as SIM swapping. Attackers also try prompt bombing, sending repeated approval requests until a tired user taps accept. Stronger choices include app prompts that require entering a displayed number and phishing-resistant methods such as security keys or passkeys. A practical approach is to start with what staff will actually use, then move higher-risk accounts to stronger methods.

Myth 5: It is too expensive or too hard to roll out

Reality: Many tools you already own include MFA. Microsoft 365 and Google Workspace both offer it, and many EHR and remote access products support it too. The cost is often more in planning and training than in licenses. A phased rollout, starting with administrators and email, spreads the effort.

Where to Start: A Priority List

Administrator and privileged accounts. These are the keys to everything.

Email. A compromised mailbox leads to fraud and further breaches.

Remote access, such as VPN and remote desktop.

Cloud applications that hold resident or financial data.

EHR and clinical systems, where supported and workable on the floor.

Everything else, over time.

Rolling It Out Smoothly

Pilot with a small group. Start with leadership and office staff to uncover issues.

Communicate early. Explain why, what staff will see and who to call.

Provide hands-on enrollment help. Hold short sessions on each shift.

Plan for lost phones and new hires. Document how to reset or enroll a device and verify identity before doing so.

Keep emergency access. Maintain a small number of secured break-glass accounts so you are not locked out during an outage.

Avoid exceptions that become permanent. Track and review any account excluded from MFA.

Remember: MFA Is Not the Whole Plan

MFA greatly reduces risk but does not replace patching, backups, staff training or monitoring. HIPAA's Security Rule calls for person or entity authentication, and MFA is a strong way to meet that expectation, but it works best as part of layered protection.

A Simple Next Step

Make a list of every system that holds resident information or lets people connect remotely, and mark which ones require more than a password today. The unchecked ones become your rollout plan.

UnityCare IT helps healthcare organizations turn on and manage MFA in ways that fit care workflows, from email and remote access to shared workstation sign-in. If you would like to talk through options, we are happy to help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034