A stolen password is one of the most common ways attackers get into email accounts, remote access tools and cloud applications. Multi-factor authentication, or MFA, adds a second proof of identity, such as a code on a phone or a tap on an approval prompt, so a password alone is not enough. CISA and other security authorities consistently recommend MFA as one of the highest-value protections an organization can adopt.
The technology is straightforward. The hard part is getting a busy care team to accept it. Staff who chart on shared workstations, work odd hours or do not carry smartphones on shift will not embrace a method that slows them down. This guide focuses on doing it the right way.
If you cannot do everything at once, prioritize by risk:
Email, including webmail, since it controls password resets for almost everything else
Remote access such as VPN, remote desktop gateways and virtual desktops
Administrator and IT accounts on any system
Cloud applications that contain resident information or financial data
Payroll, banking and billing portals
EHR access from outside the facility
On-site clinical workstations may come later, using methods suited to shift work.
Not all MFA methods are equal. Consider the tradeoffs:
Authenticator app with push or code: a good balance of security and convenience for staff with smartphones.
Number matching prompts: require the user to enter a number shown on the sign-in screen, which helps defend against accidental approvals.
Hardware security keys: very strong and phishing resistant, useful for administrators and shared workstations.
Badge or proximity cards combined with a PIN: fast for clinical floors.
Text message codes: better than nothing, but weaker, since phone numbers can be hijacked. Use them only when other options are not feasible.
Phone call verification: a fallback for staff without smartphones, with similar weaknesses.
If staff do not want work apps on personal phones, provide alternatives such as hardware keys or facility-owned devices rather than forcing the issue.
A phased plan reduces disruption:
Pilot. Start with IT and a small group of volunteers to find problems.
Communicate. Explain what is changing, when and why, in plain language. Connect it to protecting residents and staff.
Train. Provide a one-page guide with screenshots and offer in-person help sessions across shifts, including nights and weekends.
Enroll in waves. Do a department at a time, with support staff available.
Support. Staff the helpdesk well during the first weeks.
Does this track my personal phone? Authenticator apps generally do not give the employer access to personal data, but be ready to explain exactly what is and is not collected.
What if I lose my phone? Have a documented, secure recovery process that verifies identity before resetting.
Will I have to do this every time? Many systems can remember trusted devices or sessions for a period, balancing convenience and risk.
What about contractors and agency staff? Include them in the policy, with tailored onboarding and offboarding.
Legacy email protocols that bypass MFA should be turned off
Service accounts and shared mailboxes may need special handling
Attackers may bombard users with prompts hoping for an accidental approval, so train staff to deny unexpected prompts and report them
Backup codes should be stored securely
Do not exempt executives, since they are prime targets
Record your MFA policy, covered systems and exceptions. The HIPAA Security Rule requires access controls and person or entity authentication, and MFA is a widely accepted way to strengthen both. Review exceptions regularly and remove them when alternatives become available. Make MFA part of onboarding and offboarding checklists so new accounts are enrolled and departing staff are removed promptly.
Track the percentage of accounts covered, the number of helpdesk tickets related to MFA, and blocked sign-in attempts. Share improvements with leadership to maintain support.
MFA works best when it is planned around real workflows. UnityCare IT can help you select methods, configure them across your email, remote access and cloud systems, and support your staff through the transition.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172