Multi-Factor Authentication: Rolling It Out Without Revolt

A stolen password is one of the most common ways attackers get into email accounts, remote access tools and cloud applications. Multi-factor authentication, or MFA, adds a second proof of identity, such as a code on a phone or a tap on an approval prompt, so a password alone is not enough. CISA and other security authorities consistently recommend MFA as one of the highest-value protections an organization can adopt.

The technology is straightforward. The hard part is getting a busy care team to accept it. Staff who chart on shared workstations, work odd hours or do not carry smartphones on shift will not embrace a method that slows them down. This guide focuses on doing it the right way.

Where to Turn On MFA First

If you cannot do everything at once, prioritize by risk:

Email, including webmail, since it controls password resets for almost everything else

Remote access such as VPN, remote desktop gateways and virtual desktops

Administrator and IT accounts on any system

Cloud applications that contain resident information or financial data

Payroll, banking and billing portals

EHR access from outside the facility

On-site clinical workstations may come later, using methods suited to shift work.

Choosing Methods That Fit Your Workforce

Not all MFA methods are equal. Consider the tradeoffs:

Authenticator app with push or code: a good balance of security and convenience for staff with smartphones.

Number matching prompts: require the user to enter a number shown on the sign-in screen, which helps defend against accidental approvals.

Hardware security keys: very strong and phishing resistant, useful for administrators and shared workstations.

Badge or proximity cards combined with a PIN: fast for clinical floors.

Text message codes: better than nothing, but weaker, since phone numbers can be hijacked. Use them only when other options are not feasible.

Phone call verification: a fallback for staff without smartphones, with similar weaknesses.

If staff do not want work apps on personal phones, provide alternatives such as hardware keys or facility-owned devices rather than forcing the issue.

Plan the Rollout

A phased plan reduces disruption:

Pilot. Start with IT and a small group of volunteers to find problems.

Communicate. Explain what is changing, when and why, in plain language. Connect it to protecting residents and staff.

Train. Provide a one-page guide with screenshots and offer in-person help sessions across shifts, including nights and weekends.

Enroll in waves. Do a department at a time, with support staff available.

Support. Staff the helpdesk well during the first weeks.

Anticipate Common Questions

Does this track my personal phone? Authenticator apps generally do not give the employer access to personal data, but be ready to explain exactly what is and is not collected.

What if I lose my phone? Have a documented, secure recovery process that verifies identity before resetting.

Will I have to do this every time? Many systems can remember trusted devices or sessions for a period, balancing convenience and risk.

What about contractors and agency staff? Include them in the policy, with tailored onboarding and offboarding.

Watch for Weak Spots

Legacy email protocols that bypass MFA should be turned off

Service accounts and shared mailboxes may need special handling

Attackers may bombard users with prompts hoping for an accidental approval, so train staff to deny unexpected prompts and report them

Backup codes should be stored securely

Do not exempt executives, since they are prime targets

Document and Maintain

Record your MFA policy, covered systems and exceptions. The HIPAA Security Rule requires access controls and person or entity authentication, and MFA is a widely accepted way to strengthen both. Review exceptions regularly and remove them when alternatives become available. Make MFA part of onboarding and offboarding checklists so new accounts are enrolled and departing staff are removed promptly.

Measure Success

Track the percentage of accounts covered, the number of helpdesk tickets related to MFA, and blocked sign-in attempts. Share improvements with leadership to maintain support.

Support for the Journey

MFA works best when it is planned around real workflows. UnityCare IT can help you select methods, configure them across your email, remote access and cloud systems, and support your staff through the transition.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172