If you ask security professionals for one control that prevents the most common account takeovers, many will say multi-factor authentication, often shortened to MFA. It requires a second proof of identity, such as a code or an approval on a phone, in addition to a password. Stolen passwords alone then stop being enough.
The challenge for a nursing home, assisted living community or clinic is not understanding the value. It is deciding where to start without disrupting care. Nurses on a medication pass cannot wait for a code every five minutes. Here is a practical order of operations.
Prioritize by blast radius, meaning how much damage an attacker could do with that one login.
Anyone who can create users, change settings or reach servers should be protected first, with no exceptions. This includes accounts held by your IT provider. Ask your vendor in writing whether every technician with access to your environment uses MFA.
Email is the front door. Attackers who control a mailbox can reset other passwords, impersonate your administrator to request wire transfers and read attachments containing resident information. Turn MFA on for every mailbox, starting with leadership, business office and medical records staff.
Any way into your network from outside, such as a VPN, remote desktop gateway or virtual desktop, should require MFA. Exposed remote access without a second factor is one of the most common ways ransomware operators get in.
This includes your EMR or EHR portal where supported, payroll and HR platforms, billing and clearinghouse portals, and any file-sharing service. Check each vendor's security settings page. Many offer MFA that is simply not switched on by default.
On the floor, speed and shared workstations make some MFA methods impractical. Options to discuss with your IT partner:
Badge tap or proximity-card sign-in at shared workstations, combined with a PIN
Authenticator app push approvals on a facility-owned device for staff who do not carry personal phones
Hardware security keys for staff who sign in many times per shift
Longer, risk-based session policies, so staff are challenged on new devices or unusual locations rather than every login
The right answer depends on your EMR, your workstation setup and your staff. A short pilot on one unit will reveal friction before you roll out facility-wide.
Not all second factors are equal.
Authenticator apps and push approvals are strong for most organizations. Enable number matching where available so users must confirm a code shown on screen, which reduces approval fatigue attacks.
Hardware keys are the strongest common option for high-risk accounts.
Text message codes are better than nothing, but they can be intercepted or redirected through SIM swapping. Use them as a fallback, not a first choice.
Expect lost phones, new phones and staff who are locked out on a Sunday. Before launch:
Define how identity is verified when someone requests an MFA reset, so attackers cannot talk their way in by phone.
Decide who can approve a reset after hours.
Document backup methods for each user.
Brief your charge nurses so they know how to escalate quickly.
Staff accept MFA more readily when they understand it protects them, their paychecks and their residents. A short huddle and a one-page how-to usually works better than a long email. Tell them what to do if they receive an approval request they did not initiate: deny it and report it right away.
A reasonable plan is to cover administrator accounts this week, email and remote access within a month, and cloud applications and clinical workflows over the following quarter. Track coverage in a simple spreadsheet showing each system and whether MFA is enforced.
UnityCare IT can audit where MFA is and is not enforced across your email, remote access and cloud tools, and help you roll it out in stages that respect how care teams actually work.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034