Multi-factor authentication, often shortened to MFA, asks users for something beyond a password, such as a code or an approval on a phone. It is one of the most effective steps a healthcare organization can take against stolen credentials, and cyber insurers increasingly expect it. But MFA projects in nursing homes and senior-living communities often stall or backfire, not because the technology is bad, but because the rollout ignored how care teams actually work.
A surprise switch-over is the fastest way to flood the helpdesk and sour staff on the idea. People get locked out during shift change, nobody knows how to approve a prompt, and leadership is tempted to turn it off again.
A better path is phased: start with administrators and IT accounts, then email and remote access, then the rest of the staff in groups. Pilot with a friendly unit or department and fix problems before expanding.
Some care staff do not want to use a personal phone for work, and some units restrict phones on the floor. Requiring an app on a personal device without discussion creates resentment and sometimes a policy conflict.
Offer options:
An authenticator app for those who are comfortable with it.
Hardware security keys or tokens for staff who do not use phones at work.
Text message or phone call codes as a fallback, understanding these are weaker than app-based or hardware methods but still far better than a password alone.
Be clear about reimbursement or privacy questions, such as what the organization can and cannot see on a personal phone.
Nurse stations, medication carts and kiosks are used by many people across a shift. Prompting for a code on every login can slow down care. Think through the workflow before you enforce it.
Options include badge tap solutions, hardware keys that stay with the person, and policies that apply stronger MFA when a user logs in remotely or accesses sensitive applications, with a lighter approach for devices inside a managed, locked-down environment. Your IT provider can help match the approach to the risk.
People lose phones, replace them, forget devices at home and travel. If there is no clear and secure process for resetting MFA, the helpdesk either gets stuck or, worse, gets talked into resetting it for an attacker pretending to be an employee.
Write a procedure:
Verify the person through a method that does not depend on the lost device, such as a call to a known number or confirmation by a supervisor.
Log every reset.
Issue temporary access with a short expiration.
Require re-enrollment promptly.
MFA on email is a good first step, but attackers go where protection is weaker. Check whether your VPN or remote access, EMR portals, cloud storage, remote management tools and administrator accounts all require MFA. Old email protocols that cannot prompt for a second factor should be disabled so they cannot be used to bypass it.
Some MFA systems send a simple approve or deny prompt. Attackers who already have a password can send prompt after prompt, hoping the user taps approve just to make it stop. Train staff that an unexpected prompt means someone else has their password. They should deny it and report it right away. Where possible, use number-matching or similar features that require the user to enter something shown on the login screen.
Staff should hear about the change in advance and in plain language: why we are doing this, what will change, how long it takes, and who to call. A one-page guide with screenshots and a short huddle goes a long way. Include a message that MFA is not a sign of distrust. It protects them and their residents.
Weeks 1 to 2: inventory systems, choose methods, and write the reset procedure.
Weeks 3 to 4: enroll administrators and IT, then pilot with one department.
Weeks 5 to 8: expand in groups, with extra helpdesk coverage around each go-live.
After: review sign-in logs, remove exceptions, and add MFA to remaining systems.
The exact schedule depends on your size and staffing, but the order matters more than the speed.
UnityCare IT has helped healthcare organizations introduce MFA in ways that fit shift work and shared devices. If you are planning a rollout, or if an earlier attempt was paused, we can help you design a plan your staff will actually follow.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172