A stolen password is one of the most common ways attackers get into email, remote access tools and cloud systems. Multi-factor authentication (MFA) adds a second proof of identity, such as a code or an approval on a phone, so a password alone is not enough. For healthcare organizations, MFA is among the most effective low-cost steps available, and it is widely recommended in CISA guidance and the HHS 405(d) practices.
The challenge is rarely the technology. It is making the rollout smooth for busy staff who share workstations and have little patience for extra steps. A phased plan helps.
Not every account needs MFA on day one. Prioritize by risk:
Administrator and IT accounts
Email, including leadership and business office accounts
Remote access: VPN, remote desktop and any cloud portals
Your EHR and other systems holding resident information, where the vendor supports it
Banking, payroll and payer portals
Everything else
Email deserves special attention, since attackers use it to reset passwords for other systems and to impersonate leaders.
Apps on a smartphone are a good balance of security and convenience. Use number matching if available, so staff must type a number shown on screen rather than tapping approve blindly.
Small physical keys are very secure and resistant to phishing. They work well for administrators and for shared workstations where staff do not carry personal phones.
Better than nothing, but easier to intercept or trick someone into sharing. Use as a fallback rather than a first choice.
Security questions are not true MFA and are easy to guess or look up.
Shared workstations and carts: Consider badge tap, hardware keys or short-session policies, so that nurses are not typing codes at every chart opening.
Staff without smartphones or who do not want work apps on personal phones: Offer hardware tokens or facility-issued devices. Make your policy clear and fair.
Spotty reception in some areas: Authenticator apps generate codes without a cell signal.
Part-time and agency staff: Include them in the plan rather than leaving them with weaker access.
Start with a small group: IT, administration and one or two friendly department heads. Gather feedback on what is confusing. Fix instructions, then expand by department.
Staff accept MFA more readily when they understand why. Explain in plain language that it protects residents' information and also protects their own accounts. Provide:
A one-page how-to with screenshots
A date for each group
A drop-in help session during shift overlap
A phone number for lockouts
Employees will lose phones and change numbers. Define a verified process for resetting MFA, so attackers cannot call the helpdesk and impersonate staff. Require identity checks, such as a call-back to a known number or confirmation from a supervisor.
Attackers sometimes send repeated approval prompts, hoping a tired employee taps accept. Teach staff to deny unexpected prompts and report them immediately.
Record which systems have MFA enabled, which exceptions exist and why, and review it quarterly. Exceptions should have an owner and an end date. This documentation also supports your HIPAA risk analysis.
A small facility can often cover email and remote access in a few weeks, then add other systems over a few months. The key is to keep going rather than stopping after email.
UnityCare IT helps healthcare providers plan and deploy MFA, including workable options for shared workstations and staff without smartphones. If you want a prioritized list of accounts and a rollout schedule, we can help you build one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172