Multi-factor authentication, often shortened to MFA, asks for something beyond a password, such as a code or an approval on a phone. It is one of the most widely recommended security controls, including in CISA guidance and the HHS 405(d) Health Industry Cybersecurity Practices. Yet in senior living and long-term care settings, it still meets resistance.
Most of that resistance comes from a handful of myths. Here is what we hear most often, and what is actually true.
Attackers rarely choose targets by size. Automated tools test stolen passwords against thousands of email and cloud logins every day. If your staff reuse a password that appeared in an old breach elsewhere, a small facility is just as easy to log into as a large one. Smaller organizations also tend to have fewer security staff, which makes them attractive.
Reality: Size does not protect you. A second factor stops many attacks that rely on a stolen password alone.
Some organizations worry that aides or kitchen staff will not have, or will not want to use, personal phones for work. That concern is reasonable, but there are alternatives:
Hardware security keys or small token devices that can be kept at a station or on a badge
Authentication through a company-provided phone or shared device where appropriate
Phone-call or text options as a fallback, although these are weaker than app-based methods
Applying MFA first to the highest-risk accounts, such as email, remote access, administrators and billing
Reality: You can choose methods that fit your workforce. You do not have to use personal phones for every employee.
Nobody wants a nurse waiting on a code while a call light rings. But MFA does not have to appear every time someone touches a computer. Well-designed setups:
Prompt at sign-in, then remember trusted devices for a period
Use tap-to-approve or badge tap on shared workstations
Apply stricter requirements only for remote access or unusual locations
Exclude certain clinical workflows when risk is low and other controls are in place
Reality: Thoughtful configuration keeps friction low where speed matters most, while protecting the doors attackers prefer.
A long, unique password is a good start, but passwords can be phished, guessed, reused or stolen. A fake login page can capture even a strong password in seconds. MFA adds another barrier that the thief usually cannot pass.
Reality: Passwords and MFA work together. Neither replaces the other.
This one goes the other direction. MFA greatly reduces risk, but it is not perfect. Attackers sometimes send repeated approval requests hoping someone taps yes to make them stop, sometimes called push fatigue. Text message codes can be intercepted in certain attacks.
Reality: Use stronger methods where you can, such as app-based number matching or security keys. Train staff never to approve a prompt they did not start, and to report unexpected prompts right away.
A phased approach makes this manageable:
Phase 1: Administrators, IT accounts and anyone with access to financial systems
Phase 2: Email and remote access for all staff
Phase 3: Cloud applications, the EHR portal and vendor systems that support it
Phase 4: Shared and clinical workstations, using methods designed for those settings
Announce each phase, offer a short how-to sheet, and keep a helpdesk contact available during the first week.
Explain why. Staff accept MFA more readily when they understand it protects residents and their own paychecks.
Set up a backup method for each user, so a lost or broken phone does not lock them out.
Document how identity is verified for resets so attackers cannot talk their way past the helpdesk.
Review MFA coverage regularly. Accounts that were skipped are often the ones attackers find.
Ask your EHR and other software vendors what MFA options they support, and turn them on.
The HIPAA Security Rule requires organizations to verify the identity of people accessing electronic protected health information and to implement reasonable and appropriate safeguards based on a risk analysis. MFA is not named in the current rule text, but it is widely considered a reasonable safeguard for email and remote access.
UnityCare IT helps healthcare organizations plan and roll out MFA in a way that fits real workflows. If you are unsure where to begin, we can review your accounts and propose a phased plan.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172