Multi-factor authentication, usually shortened to MFA, is one of the most effective protections available against stolen passwords. It is also one of the most resisted. When a nurse is juggling a medication pass, an extra login step feels like an obstacle. Rolling out MFA successfully means addressing the objections head on.
Here are five myths we hear and what is actually true.
Reality: Strong passwords do not help if they are phished, reused from another site or captured by malware. Attackers do not guess passwords one at a time; they trick people into handing them over, or they reuse credentials leaked elsewhere. MFA means that a stolen password alone is not enough to get in.
Reality: Attackers use automation. They send the same phishing emails to thousands of organizations and test stolen logins everywhere. Healthcare records are valuable, and smaller organizations often have fewer defenses. Size is not protection.
Reality: Poorly designed rollouts can. Well-designed ones barely register. Options that reduce friction include:
Remembering trusted devices for a limited period on managed computers
Using push approvals or number matching instead of typing codes
Using badge tap or fingerprint readers where clinical workflow requires fast sign-in
Applying stricter requirements only for risky situations, such as logging in from outside the facility
The goal is to protect high-risk access first, such as email, remote access, administrator accounts and cloud systems, without disrupting the fast logins needed at the bedside.
Reality: Methods vary. Roughly from weakest to strongest:
Text message codes: better than nothing, but vulnerable to SIM swapping and interception
Authenticator app codes or push notifications: much stronger, though push fatigue attacks exist if approvals are not protected
Number matching push: requires the user to enter a number shown on screen, which reduces accidental approvals
Hardware security keys and passkeys: the most phishing-resistant options, increasingly supported
Start where you can, then move toward stronger methods for administrators and sensitive roles. Remind staff never to approve a prompt they did not initiate.
Reality: Plenty of staff are reluctant to install work apps on personal phones, and some do not have smartphones. Alternatives include:
Hardware tokens or small security keys
Facility-provided devices at shared stations
Phone call verification as a backup
Clear privacy information explaining that authenticator apps do not give the employer access to personal photos, messages or location
Addressing the privacy question directly goes a long way.
Turn it on first for email, remote access, VPN, cloud applications, administrator accounts and anyone with access to financial systems.
Explain why in plain language. Tie it to protecting residents and the organization, not to distrust of staff.
Run short sessions by shift. Provide a quick-reference card. Have the helpdesk ready for the first week, since lost phones and new devices are the most common issues.
Decide how someone regains access if they lose their phone. The recovery process must be secure, since attackers will try to abuse it by impersonating employees.
The HIPAA Security Rule requires person or entity authentication and access controls, and many cyber insurance applications now ask directly whether MFA is enforced for email and remote access. Being able to answer yes can influence coverage and pricing.
Before enabling MFA for everyone, choose a small pilot group that includes a nurse, an aide, a business office employee and a manager. Ask them to use it for two weeks and report what slowed them down. Their feedback will shape the instructions, reveal problems with older devices and give you credible peers who can reassure coworkers during the full rollout.
If MFA is only partly deployed in your organization, start by listing every system that holds or reaches resident data and checking which ones are covered. UnityCare IT helps healthcare teams plan rollouts that protect accounts without getting in the way of care.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172