Questions Administrators Ask About MFA, Answered

Multi-factor authentication is one of the most effective security improvements available, and yet many administrators hesitate. They worry about slowing down nurses, about staff without smartphones, about cost, and about what happens when someone is locked out. These are fair concerns, and each has a workable answer.

Below are the questions we hear most often, with straightforward responses.

What is MFA, in one sentence?

MFA requires two or more proofs of identity to sign in, such as something you know (a password) plus something you have (a phone, security key or badge) or something you are (a fingerprint). A stolen password alone is no longer enough.

Why does it matter so much?

Many breaches begin with stolen or guessed credentials, often obtained through phishing. With MFA in place, an attacker who has your password still cannot get in without the second factor. CISA and other agencies consistently recommend MFA as a priority control, and it is a core practice in the HHS 405(d) HICP guidance. It also supports the Security Rule's requirement for person or entity authentication.

Will it slow down nurses on the floor?

It can if implemented poorly, but it does not have to. Options include:

Remembering trusted devices or sessions for a reasonable period on managed workstations

Badge tap or proximity card sign-in for shared clinical workstations

Single sign-on, so one verification covers several applications

Requiring MFA at the start of a shift, rather than on every screen

Pilot with one unit, gather feedback and adjust before expanding.

What about staff who do not have smartphones or do not want to use their own?

You have alternatives:

Hardware security keys or tokens issued by the facility

Desk phone or landline voice call verification, though it is less secure than other methods

Badge-based authentication

Facility-owned mobile devices for staff who need them

Do not force personal phone use without a policy. Some organizations offer a small stipend or provide devices, depending on their approach.

Are text message codes good enough?

They are much better than nothing, but they can be intercepted or tricked through SIM swapping and phishing. Authenticator app prompts with number matching are stronger, and hardware keys are stronger still. Start with what you can deploy successfully, then move toward stronger methods for administrators and high-risk accounts.

Where should we turn it on first?

Prioritize in this order:

Email and cloud collaboration accounts

Administrator and IT accounts

Remote access, such as VPN

The EHR or other systems holding ePHI, where supported

Payroll, banking and vendor portals

Everything else

If a system does not support MFA, document that and consider compensating controls such as network restrictions.

What happens when someone loses their phone or gets locked out?

Plan for this before launch. Provide a clear process for identity verification and a temporary access method. Keep recovery codes for administrator accounts in a secure place, such as a sealed envelope in a safe. A helpdesk with extended hours is valuable here, since care does not follow business hours.

What does it cost?

Many email and cloud platforms already include MFA at no extra charge. Costs arise with hardware tokens, premium identity tools and the time spent on setup and training. Compare those costs with the cost of a compromised mailbox or a ransomware event, which can be far larger.

How do we get staff on board?

Explain the reason with a simple, concrete example

Provide step-by-step instructions with screenshots

Hold drop-in sessions during shift changes

Name champions on each unit who can help peers

Set a clear date and stick to it, with limited exceptions

What are common mistakes?

Exempting executives or administrators, who are prime targets

Leaving older protocols enabled that bypass MFA

Not reviewing registered devices when employees leave

Approving every prompt automatically, a habit attackers exploit through prompt bombing

Getting started

A phased rollout with good communication usually succeeds. UnityCare IT can help you plan MFA for your email, remote access and clinical systems, and support your staff through the transition. If you have specific concerns about your workflows, we are happy to talk them through.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172