Stolen passwords are one of the most common ways attackers get into healthcare systems. Multifactor authentication, often shortened to MFA, adds a second proof of identity so a stolen password alone is not enough. CISA and the HHS 405(d) program both recommend it as a core practice. The challenge in care settings is not whether to use it, but how to roll it out without slowing the people who are caring for residents.
This guide lays out a practical rollout.
MFA combines something you know, such as a password, with something you have or are. Common second factors include:
An authenticator app that generates codes or sends a push approval
A hardware security key
A text message code
A fingerprint or face check on a phone or laptop
Not all are equally strong. App-based approvals and hardware keys resist more attacks than text messages, though text messages are far better than no second factor. Choose the strongest option your staff can realistically use.
Do not try to protect everything on day one. Prioritize by risk:
Email and cloud services, including Microsoft 365 or Google Workspace
Remote access, such as VPN or remote desktop
Administrator accounts for servers, firewalls and cloud consoles
Your EHR and other applications that hold resident data, where supported
Vendor portals that handle payroll, banking or billing
Administrator and remote access accounts come first because the damage from a compromise is greatest.
Care teams face situations that office workers do not. Consider these early:
Several people may use the same computer through a shift. Look at tap-to-sign-in badges, proximity cards or fast user switching so that authentication takes seconds, not minutes.
Many aides and housekeeping staff do not want to use a personal phone for work. Offer alternatives such as hardware keys or badge-based options, and be clear about what the app on a personal phone can and cannot see.
If the building has poor cell coverage, text codes and push approvals may fail inside. Test this in each wing before deciding on a method.
Training must reach every shift, not only the daytime team.
People resist what surprises them. Send a short notice that covers why you are doing it, what changes, when it starts and where to get help. Use the same message at huddles and on posters. Emphasize that MFA protects residents, protects the facility and also protects their own paychecks and personal information.
Start with a pilot group of administrators and IT-friendly staff. Fix the issues they find, then extend to departments one at a time. Schedule go-live for a normal weekday morning when support staff are available, not Friday afternoon or just before a holiday.
A new phone or forgotten device is the most common support call after launch. Create a recovery process before go-live:
Verify identity before resetting an MFA method, using a known phone number or a supervisor.
Keep emergency access accounts for administrators, stored securely and tested.
Provide backup codes for users who travel or have limited phone access.
Be wary of attackers who flood users with repeated approval prompts hoping someone taps accept. Train staff to deny unexpected prompts and report them immediately.
After launch, review sign-in logs and support tickets. Look for accounts that are exempt, services that still allow password-only access and users who struggle. Close exceptions as quickly as practical and document any that remain with a reason and an end date.
The HIPAA Security Rule requires procedures to verify that a person seeking access to ePHI is who they claim to be. MFA is not named as a requirement, but it is a strong, widely recognized way to meet that expectation. Document your decisions in your risk analysis.
UnityCare IT helps healthcare organizations plan and deploy MFA, including training and the helpdesk support that makes launch week go smoothly. If you would like to talk through the best approach for your shifts and devices, get in touch.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034