Multi-Factor Authentication: Where to Turn It On First

If you ask security professionals for one control that prevents the most common account takeovers, many will say multi-factor authentication, often shortened to MFA. It requires a second proof of identity, such as a code or an approval on a phone, in addition to a password. Stolen passwords alone then stop being enough.

The challenge for a nursing home, assisted living community or clinic is not understanding the value. It is deciding where to start without disrupting care. Nurses on a medication pass cannot wait for a code every five minutes. Here is a practical order of operations.

Start with the accounts that can hurt you most

Prioritize by blast radius, meaning how much damage an attacker could do with that one login.

1. Administrator and IT accounts

Anyone who can create users, change settings or reach servers should be protected first, with no exceptions. This includes accounts held by your IT provider. Ask your vendor in writing whether every technician with access to your environment uses MFA.

2. Email and productivity suites

Email is the front door. Attackers who control a mailbox can reset other passwords, impersonate your administrator to request wire transfers and read attachments containing resident information. Turn MFA on for every mailbox, starting with leadership, business office and medical records staff.

3. Remote access

Any way into your network from outside, such as a VPN, remote desktop gateway or virtual desktop, should require MFA. Exposed remote access without a second factor is one of the most common ways ransomware operators get in.

4. Cloud applications holding resident data

This includes your EMR or EHR portal where supported, payroll and HR platforms, billing and clearinghouse portals, and any file-sharing service. Check each vendor's security settings page. Many offer MFA that is simply not switched on by default.

Handle the clinical floor thoughtfully

On the floor, speed and shared workstations make some MFA methods impractical. Options to discuss with your IT partner:

Badge tap or proximity-card sign-in at shared workstations, combined with a PIN

Authenticator app push approvals on a facility-owned device for staff who do not carry personal phones

Hardware security keys for staff who sign in many times per shift

Longer, risk-based session policies, so staff are challenged on new devices or unusual locations rather than every login

The right answer depends on your EMR, your workstation setup and your staff. A short pilot on one unit will reveal friction before you roll out facility-wide.

Pick methods wisely

Not all second factors are equal.

Authenticator apps and push approvals are strong for most organizations. Enable number matching where available so users must confirm a code shown on screen, which reduces approval fatigue attacks.

Hardware keys are the strongest common option for high-risk accounts.

Text message codes are better than nothing, but they can be intercepted or redirected through SIM swapping. Use them as a fallback, not a first choice.

Prepare for the help desk calls

Expect lost phones, new phones and staff who are locked out on a Sunday. Before launch:

Define how identity is verified when someone requests an MFA reset, so attackers cannot talk their way in by phone.

Decide who can approve a reset after hours.

Document backup methods for each user.

Brief your charge nurses so they know how to escalate quickly.

Communicate the why

Staff accept MFA more readily when they understand it protects them, their paychecks and their residents. A short huddle and a one-page how-to usually works better than a long email. Tell them what to do if they receive an approval request they did not initiate: deny it and report it right away.

Next steps

A reasonable plan is to cover administrator accounts this week, email and remote access within a month, and cloud applications and clinical workflows over the following quarter. Track coverage in a simple spreadsheet showing each system and whether MFA is enforced.

UnityCare IT can audit where MFA is and is not enforced across your email, remote access and cloud tools, and help you roll it out in stages that respect how care teams actually work.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034