Multi-Factor Authentication Rollout Plan for Small Care Facilities

A stolen password is one of the most common ways attackers get into email, remote access tools and cloud systems. Multi-factor authentication (MFA) adds a second proof of identity, such as a code or an approval on a phone, so a password alone is not enough. For healthcare organizations, MFA is among the most effective low-cost steps available, and it is widely recommended in CISA guidance and the HHS 405(d) practices.

The challenge is rarely the technology. It is making the rollout smooth for busy staff who share workstations and have little patience for extra steps. A phased plan helps.

Step 1: Decide What to Protect First

Not every account needs MFA on day one. Prioritize by risk:

Administrator and IT accounts

Email, including leadership and business office accounts

Remote access: VPN, remote desktop and any cloud portals

Your EHR and other systems holding resident information, where the vendor supports it

Banking, payroll and payer portals

Everything else

Email deserves special attention, since attackers use it to reset passwords for other systems and to impersonate leaders.

Step 2: Choose the Right Methods

Authenticator apps and push approvals

Apps on a smartphone are a good balance of security and convenience. Use number matching if available, so staff must type a number shown on screen rather than tapping approve blindly.

Hardware security keys

Small physical keys are very secure and resistant to phishing. They work well for administrators and for shared workstations where staff do not carry personal phones.

Text message codes

Better than nothing, but easier to intercept or trick someone into sharing. Use as a fallback rather than a first choice.

Methods to avoid relying on

Security questions are not true MFA and are easy to guess or look up.

Step 3: Plan for the Realities of Care Settings

Shared workstations and carts: Consider badge tap, hardware keys or short-session policies, so that nurses are not typing codes at every chart opening.

Staff without smartphones or who do not want work apps on personal phones: Offer hardware tokens or facility-issued devices. Make your policy clear and fair.

Spotty reception in some areas: Authenticator apps generate codes without a cell signal.

Part-time and agency staff: Include them in the plan rather than leaving them with weaker access.

Step 4: Pilot Before You Launch

Start with a small group: IT, administration and one or two friendly department heads. Gather feedback on what is confusing. Fix instructions, then expand by department.

Step 5: Communicate Clearly

Staff accept MFA more readily when they understand why. Explain in plain language that it protects residents' information and also protects their own accounts. Provide:

A one-page how-to with screenshots

A date for each group

A drop-in help session during shift overlap

A phone number for lockouts

Step 6: Prepare for Lockouts

Employees will lose phones and change numbers. Define a verified process for resetting MFA, so attackers cannot call the helpdesk and impersonate staff. Require identity checks, such as a call-back to a known number or confirmation from a supervisor.

Step 7: Watch for MFA Fatigue

Attackers sometimes send repeated approval prompts, hoping a tired employee taps accept. Teach staff to deny unexpected prompts and report them immediately.

Step 8: Document and Review

Record which systems have MFA enabled, which exceptions exist and why, and review it quarterly. Exceptions should have an owner and an end date. This documentation also supports your HIPAA risk analysis.

A Realistic Timeline

A small facility can often cover email and remote access in a few weeks, then add other systems over a few months. The key is to keep going rather than stopping after email.

How UnityCare IT Can Help

UnityCare IT helps healthcare providers plan and deploy MFA, including workable options for shared workstations and staff without smartphones. If you want a prioritized list of accounts and a rollout schedule, we can help you build one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172