Ask any security professional which single control blocks the most account takeovers, and multi-factor authentication (MFA) is near the top of the list. A stolen password alone is no longer enough to get into email or a cloud system when a second proof of identity is required.
Yet many nursing homes, assisted living communities and clinics have not finished their MFA rollout. The reasons are understandable: shared computers, staff without smartphones, night shifts with no IT on site, and a fear of slowing down care. This post lays out a phased approach that respects those realities.
Do not try to enable MFA everywhere in one weekend. Prioritize in this order:
Administrator and IT accounts. These can change everything.
Email and Microsoft 365 or Google Workspace. Email is the main route for phishing and password resets.
Remote access. VPNs, remote desktop gateways and any way into the network from outside.
Systems holding resident information. EMR/EHR, billing, and portals, as far as the vendor supports MFA.
Everyone else. Roll out to remaining staff by department.
This ordering protects the most valuable accounts first and gives you early wins to build confidence.
Not every method suits every role.
Authenticator app prompts or number matching are generally stronger than text-message codes and work well for staff with smartphones.
Text message or voice call codes are better than no MFA and may be the practical choice for some staff, though they are more vulnerable to SIM swapping and interception.
Hardware security keys suit administrators and high-risk roles, and can work for staff who do not want to use a personal phone.
Badge or proximity tap solutions can help on shared clinical workstations where logging in repeatedly would slow care.
If you expect staff to use personal phones, put that in writing. Many people worry that an app gives the employer access to their device, and a clear explanation avoids resistance.
Shared nurse station computers are the hardest case. Options include:
Using single sign-on with a tap-in badge, so staff authenticate quickly and sessions end automatically
Setting short, sensible auto-lock timers rather than constant re-prompting
Giving each user their own login rather than a shared one, since shared logins undermine both MFA and audit trails
HIPAA's Security Rule expects unique user identification and access controls, so a shared generic login is a compliance problem on its own, regardless of MFA.
Most MFA complaints come from surprise. Before each wave:
Explain why in plain language: stolen passwords are common, and this protects residents' information and their own accounts.
Provide a one-page how-to with screenshots.
Hold short sessions at shift change so night and weekend staff are not left out.
Tell people who to call and what hours help is available.
Expect a spike in tickets the first week. Prepare for:
Lost or replaced phones
Staff who forgot to enroll
Prompts that never arrive
Employees working abroad or in poor signal areas
Decide in advance how you will verify someone's identity before resetting their MFA. A scammer posing as an employee who lost a phone is a real tactic, so the reset process must be as careful as the login itself.
After rollout, review regularly:
Which accounts still do not have MFA enabled?
Are old authentication methods, such as legacy email protocols, still allowing logins without MFA?
Are service accounts and shared mailboxes covered by compensating controls?
Are departing employees' devices removed from their MFA registrations?
These leftovers are exactly what attackers look for.
For a facility with one or two hundred users, a phased rollout over four to eight weeks is typical: administrators in the first week, email in the next couple of weeks, then departments in waves. Larger or multi-site organizations take longer, and that is fine. A steady, communicated rollout beats a rushed one that gets switched off after complaints.
UnityCare IT helps healthcare organizations plan and deploy MFA, including the awkward shared-workstation cases, and supports staff through the transition. If you are not sure where your gaps are, we can start with a quick review of which accounts are and are not protected.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172