Multi-Factor Authentication: Five Myths Staff Believe

Multi-factor authentication, usually shortened to MFA, is one of the most effective protections available against stolen passwords. It is also one of the most resisted. When a nurse is juggling a medication pass, an extra login step feels like an obstacle. Rolling out MFA successfully means addressing the objections head on.

Here are five myths we hear and what is actually true.

Myth 1: Our passwords are strong, so we do not need it

Reality: Strong passwords do not help if they are phished, reused from another site or captured by malware. Attackers do not guess passwords one at a time; they trick people into handing them over, or they reuse credentials leaked elsewhere. MFA means that a stolen password alone is not enough to get in.

Myth 2: We are too small to be a target

Reality: Attackers use automation. They send the same phishing emails to thousands of organizations and test stolen logins everywhere. Healthcare records are valuable, and smaller organizations often have fewer defenses. Size is not protection.

Myth 3: MFA will slow down patient care

Reality: Poorly designed rollouts can. Well-designed ones barely register. Options that reduce friction include:

Remembering trusted devices for a limited period on managed computers

Using push approvals or number matching instead of typing codes

Using badge tap or fingerprint readers where clinical workflow requires fast sign-in

Applying stricter requirements only for risky situations, such as logging in from outside the facility

The goal is to protect high-risk access first, such as email, remote access, administrator accounts and cloud systems, without disrupting the fast logins needed at the bedside.

Myth 4: All MFA is equally secure

Reality: Methods vary. Roughly from weakest to strongest:

Text message codes: better than nothing, but vulnerable to SIM swapping and interception

Authenticator app codes or push notifications: much stronger, though push fatigue attacks exist if approvals are not protected

Number matching push: requires the user to enter a number shown on screen, which reduces accidental approvals

Hardware security keys and passkeys: the most phishing-resistant options, increasingly supported

Start where you can, then move toward stronger methods for administrators and sensitive roles. Remind staff never to approve a prompt they did not initiate.

Myth 5: Staff without smartphones cannot use it

Reality: Plenty of staff are reluctant to install work apps on personal phones, and some do not have smartphones. Alternatives include:

Hardware tokens or small security keys

Facility-provided devices at shared stations

Phone call verification as a backup

Clear privacy information explaining that authenticator apps do not give the employer access to personal photos, messages or location

Addressing the privacy question directly goes a long way.

Rolling it out well

Prioritize

Turn it on first for email, remote access, VPN, cloud applications, administrator accounts and anyone with access to financial systems.

Communicate

Explain why in plain language. Tie it to protecting residents and the organization, not to distrust of staff.

Train and support

Run short sessions by shift. Provide a quick-reference card. Have the helpdesk ready for the first week, since lost phones and new devices are the most common issues.

Plan for recovery

Decide how someone regains access if they lose their phone. The recovery process must be secure, since attackers will try to abuse it by impersonating employees.

HIPAA and cyber insurance

The HIPAA Security Rule requires person or entity authentication and access controls, and many cyber insurance applications now ask directly whether MFA is enforced for email and remote access. Being able to answer yes can influence coverage and pricing.

Test with a pilot group

Before enabling MFA for everyone, choose a small pilot group that includes a nurse, an aide, a business office employee and a manager. Ask them to use it for two weeks and report what slowed them down. Their feedback will shape the instructions, reveal problems with older devices and give you credible peers who can reassure coworkers during the full rollout.

Next step

If MFA is only partly deployed in your organization, start by listing every system that holds or reaches resident data and checking which ones are covered. UnityCare IT helps healthcare teams plan rollouts that protect accounts without getting in the way of care.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172