Rolling Out Multi-Factor Authentication Without Slowing Care

Multi-factor authentication, or MFA, asks a user to prove who they are with something more than a password, such as a code from an app or a prompt on their phone. It is one of the most effective controls against stolen passwords, which is how many attackers get in. It is also one of the most resisted by busy clinical staff, who do not have time for extra steps while a resident is waiting.

The answer is not to skip MFA. It is to roll it out thoughtfully.

Start with the highest-risk accounts

Not every login carries the same risk. Begin with:

Administrator and IT accounts, which can change everything.

Email, especially for leadership, the business office and anyone who handles payments.

Remote access such as VPN or virtual desktop.

Cloud applications that contain resident information.

Backup and security consoles.

These groups are smaller, more technical and easier to support. Success here builds confidence for broader rollout.

Choose methods that fit the workplace

There is more than one way to do MFA, and the best choice depends on the setting:

Authenticator app prompts. Convenient and more secure than text messages for most staff with smartphones.

Hardware security keys. Excellent for administrators and for shared workstations, and not dependent on a personal phone.

Badge or tap-based sign-in. Useful at nurse stations where speed matters, if your systems support it.

Text message codes. Better than nothing, but more vulnerable to interception than app-based methods.

Address the personal phone question early. Some employees will not want work software on their own phones. Offer alternatives such as hardware keys, and put a clear policy in writing.

Handle shared workstations carefully

Nurse station computers and workstations on wheels are where MFA is hardest. Consider:

Fast sign-in using badges combined with a PIN.

Short, sensible session timeouts rather than constant re-prompting.

Remembering trusted devices for a limited period on managed, locked-down computers.

Separate rules for kiosks that only display non-sensitive information.

Work with your director of nursing to watch a real shift and time how long sign-in takes. Design around the real workflow.

Communicate before you switch it on

Most resistance comes from surprise. Plan communication:

Explain why in plain language. Stolen passwords are common, and MFA stops most attempts to use them.

Announce a date, and give a short how-to guide with screenshots.

Offer drop-in help sessions on each shift, including nights and weekends.

Tell staff exactly who to call if they lose their phone or get locked out.

Prepare for lockouts and lost phones

Some staff will lose a phone or buy a new one. Have a documented process for verifying identity before resetting MFA, because attackers also call helpdesks pretending to be locked-out employees. Require a verification step such as a call-back to a known number or approval from a supervisor.

Roll out in phases

A realistic timeline might look like this:

Week one: IT and administrators.

Weeks two and three: leadership, business office and remote users.

Weeks four through six: clinical and department staff, one unit or shift at a time.

Afterward: review help requests, adjust settings and close gaps.

Track which accounts are covered and which are not. Exceptions should be rare, documented and revisited regularly.

Watch for MFA fatigue

Attackers sometimes send repeated prompts hoping a tired employee will approve one. Train staff to deny any prompt they did not initiate and to report it. Where possible, use number-matching or similar features that require the user to confirm a code shown on the screen.

Connect it to your HIPAA risk analysis

HIPAA requires reasonable safeguards for access to electronic protected health information. MFA is not named as a requirement in the current Security Rule, but it is widely recognized as a sensible safeguard, and documenting your decisions in your risk analysis shows thoughtful management.

How UnityCare IT can help

UnityCare IT helps healthcare and senior living organizations plan and deploy MFA, from choosing methods to training staff and supporting the first weeks. If you would like help mapping your accounts and choosing a rollout plan, we are glad to talk it through.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172