Multi-factor authentication, or MFA, is one of the most effective protections a healthcare organization can add. It means a stolen password alone is not enough to get in. It is also one of the projects that most often stalls, usually because of worries about nurses, shared computers and the helpdesk call volume that follows.
This checklist walks through a rollout that works in a real clinic or care facility.
Email and Microsoft 365 or Google Workspace accounts, first. These are the most commonly attacked.
Remote access, VPN and any cloud portals that hold patient information.
The EHR or EMR, including PointClickCare or similar systems, if the vendor supports it.
Administrator accounts of every kind. These must be first, not last.
List who needs access, on which devices, and from where. Note shared workstations, medication carts, kiosks and staff who do not carry a smartphone. Each group may need a different method.
Not every method is equal.
Authenticator app with number matching: strong and free for most staff.
Hardware security keys: excellent for administrators and shared workstations.
Text message codes: better than nothing, but easier to attack. Use only where nothing else works.
Phone call approval: a last resort.
Avoid approve or deny prompts without number matching, because attackers send repeated prompts hoping someone taps approve.
Do not require personal phones without a plan. Options include hardware tokens, an organization-provided device, or a policy that clearly explains what is voluntary. Address privacy concerns in writing: an authenticator app does not give the employer access to a personal phone.
Fast user switching and badge tap-in can pair well with MFA. Talk to your vendor about options that do not force a code every time a nurse steps up to a cart.
Decide in advance how access works when the identity system is down, when a phone is lost, or when a new hire starts. Create two break-glass administrator accounts with strong passwords, kept offline and monitored.
Start with IT, administration and a handful of willing clinicians. Gather problems and fix instructions.
Tell staff why, when and what they will see. A short one-page guide with screenshots does more than a long policy.
Move department by department, avoiding high-workload times such as shift change or the first of the month. Offer in-person help on the first morning.
A registration window of a couple of weeks, followed by a firm date, works well. Without a deadline, a few accounts stay unprotected, and those are the ones attackers find.
Review accounts that have not enrolled.
Set the process for lost phones and replaced devices, including identity verification by the helpdesk.
Add MFA to the new-hire and offboarding checklists.
Watch for MFA fatigue attacks: repeated prompts users did not trigger should be reported immediately.
Review settings yearly as vendors add stronger options.
Leaving old email protocols, which bypass MFA, switched on.
Excluding executives because they find it inconvenient. They are prime targets.
Skipping service accounts and shared mailboxes without a compensating control.
Training nobody, then blaming staff for tapping the wrong button.
The HIPAA Security Rule requires person or entity authentication. MFA is not named in the current rule, but it is widely considered a reasonable and appropriate safeguard, and the HHS 405(d) Health Industry Cybersecurity Practices list it as a core protection for email and remote access.
UnityCare IT plans and supports MFA rollouts for clinics and long-term care operators, including pilot groups, staff guides and helpdesk coverage in the first weeks. If you would like a rollout plan fitted to your building and your staff, we are happy to help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034