Multi-factor authentication is one of the most effective security improvements available, and yet many administrators hesitate. They worry about slowing down nurses, about staff without smartphones, about cost, and about what happens when someone is locked out. These are fair concerns, and each has a workable answer.
Below are the questions we hear most often, with straightforward responses.
MFA requires two or more proofs of identity to sign in, such as something you know (a password) plus something you have (a phone, security key or badge) or something you are (a fingerprint). A stolen password alone is no longer enough.
Many breaches begin with stolen or guessed credentials, often obtained through phishing. With MFA in place, an attacker who has your password still cannot get in without the second factor. CISA and other agencies consistently recommend MFA as a priority control, and it is a core practice in the HHS 405(d) HICP guidance. It also supports the Security Rule's requirement for person or entity authentication.
It can if implemented poorly, but it does not have to. Options include:
Remembering trusted devices or sessions for a reasonable period on managed workstations
Badge tap or proximity card sign-in for shared clinical workstations
Single sign-on, so one verification covers several applications
Requiring MFA at the start of a shift, rather than on every screen
Pilot with one unit, gather feedback and adjust before expanding.
You have alternatives:
Hardware security keys or tokens issued by the facility
Desk phone or landline voice call verification, though it is less secure than other methods
Badge-based authentication
Facility-owned mobile devices for staff who need them
Do not force personal phone use without a policy. Some organizations offer a small stipend or provide devices, depending on their approach.
They are much better than nothing, but they can be intercepted or tricked through SIM swapping and phishing. Authenticator app prompts with number matching are stronger, and hardware keys are stronger still. Start with what you can deploy successfully, then move toward stronger methods for administrators and high-risk accounts.
Prioritize in this order:
Email and cloud collaboration accounts
Administrator and IT accounts
Remote access, such as VPN
The EHR or other systems holding ePHI, where supported
Payroll, banking and vendor portals
Everything else
If a system does not support MFA, document that and consider compensating controls such as network restrictions.
Plan for this before launch. Provide a clear process for identity verification and a temporary access method. Keep recovery codes for administrator accounts in a secure place, such as a sealed envelope in a safe. A helpdesk with extended hours is valuable here, since care does not follow business hours.
Many email and cloud platforms already include MFA at no extra charge. Costs arise with hardware tokens, premium identity tools and the time spent on setup and training. Compare those costs with the cost of a compromised mailbox or a ransomware event, which can be far larger.
Explain the reason with a simple, concrete example
Provide step-by-step instructions with screenshots
Hold drop-in sessions during shift changes
Name champions on each unit who can help peers
Set a clear date and stick to it, with limited exceptions
Exempting executives or administrators, who are prime targets
Leaving older protocols enabled that bypass MFA
Not reviewing registered devices when employees leave
Approving every prompt automatically, a habit attackers exploit through prompt bombing
A phased rollout with good communication usually succeeds. UnityCare IT can help you plan MFA for your email, remote access and clinical systems, and support your staff through the transition. If you have specific concerns about your workflows, we are happy to talk them through.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172