Multi-Factor Authentication Myths Heard in Senior Living

Multi-factor authentication, often shortened to MFA, asks for something beyond a password, such as a code or an approval on a phone. It is one of the most widely recommended security controls, including in CISA guidance and the HHS 405(d) Health Industry Cybersecurity Practices. Yet in senior living and long-term care settings, it still meets resistance.

Most of that resistance comes from a handful of myths. Here is what we hear most often, and what is actually true.

Myth 1: We Are Too Small to Be a Target

Attackers rarely choose targets by size. Automated tools test stolen passwords against thousands of email and cloud logins every day. If your staff reuse a password that appeared in an old breach elsewhere, a small facility is just as easy to log into as a large one. Smaller organizations also tend to have fewer security staff, which makes them attractive.

Reality: Size does not protect you. A second factor stops many attacks that rely on a stolen password alone.

Myth 2: Our Staff Do Not Have Smartphones

Some organizations worry that aides or kitchen staff will not have, or will not want to use, personal phones for work. That concern is reasonable, but there are alternatives:

Hardware security keys or small token devices that can be kept at a station or on a badge

Authentication through a company-provided phone or shared device where appropriate

Phone-call or text options as a fallback, although these are weaker than app-based methods

Applying MFA first to the highest-risk accounts, such as email, remote access, administrators and billing

Reality: You can choose methods that fit your workforce. You do not have to use personal phones for every employee.

Myth 3: It Will Slow Down Care

Nobody wants a nurse waiting on a code while a call light rings. But MFA does not have to appear every time someone touches a computer. Well-designed setups:

Prompt at sign-in, then remember trusted devices for a period

Use tap-to-approve or badge tap on shared workstations

Apply stricter requirements only for remote access or unusual locations

Exclude certain clinical workflows when risk is low and other controls are in place

Reality: Thoughtful configuration keeps friction low where speed matters most, while protecting the doors attackers prefer.

Myth 4: Strong Passwords Are Enough

A long, unique password is a good start, but passwords can be phished, guessed, reused or stolen. A fake login page can capture even a strong password in seconds. MFA adds another barrier that the thief usually cannot pass.

Reality: Passwords and MFA work together. Neither replaces the other.

Myth 5: MFA Cannot Be Bypassed

This one goes the other direction. MFA greatly reduces risk, but it is not perfect. Attackers sometimes send repeated approval requests hoping someone taps yes to make them stop, sometimes called push fatigue. Text message codes can be intercepted in certain attacks.

Reality: Use stronger methods where you can, such as app-based number matching or security keys. Train staff never to approve a prompt they did not start, and to report unexpected prompts right away.

Myth 6: It Is Too Hard to Roll Out

A phased approach makes this manageable:

Phase 1: Administrators, IT accounts and anyone with access to financial systems

Phase 2: Email and remote access for all staff

Phase 3: Cloud applications, the EHR portal and vendor systems that support it

Phase 4: Shared and clinical workstations, using methods designed for those settings

Announce each phase, offer a short how-to sheet, and keep a helpdesk contact available during the first week.

Practical Rollout Tips

Explain why. Staff accept MFA more readily when they understand it protects residents and their own paychecks.

Set up a backup method for each user, so a lost or broken phone does not lock them out.

Document how identity is verified for resets so attackers cannot talk their way past the helpdesk.

Review MFA coverage regularly. Accounts that were skipped are often the ones attackers find.

Ask your EHR and other software vendors what MFA options they support, and turn them on.

A Note on Compliance

The HIPAA Security Rule requires organizations to verify the identity of people accessing electronic protected health information and to implement reasonable and appropriate safeguards based on a risk analysis. MFA is not named in the current rule text, but it is widely considered a reasonable safeguard for email and remote access.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations plan and roll out MFA in a way that fits real workflows. If you are unsure where to begin, we can review your accounts and propose a phased plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172