Multifactor authentication, often shortened to MFA, asks for something beyond a password, usually a code or approval from a phone or a hardware key. It is one of the most effective protections available because a stolen password alone no longer opens the door. It is also one of the protections care teams complain about most when it is rolled out badly.
The difference between a smooth rollout and a rebellion is almost always planning. Here is a sequence that works in facilities with shift staff, shared workstations and mixed technical comfort.
You do not have to cover everything on day one. Prioritize in this order:
Email, since a compromised mailbox is the starting point for many incidents
Remote access, including VPN and remote desktop
Administrator and IT accounts
Cloud applications that contain resident or financial information
Your EHR or electronic health record portal, where the vendor supports it
Many vendors, including major EHR platforms, offer their own MFA options. Ask your vendor what is available.
Not every employee has a smartphone they want to use for work, and some units restrict phones near residents or during care.
Push approval or number-matching apps are secure and convenient for staff with smartphones. Number matching, where the user types a number shown on the login screen, reduces accidental approvals.
For shared workstations, a physical key or badge tap can be faster than typing codes, and does not require a personal phone.
Better than nothing, but easier to attack. Use only where nothing else is workable.
Providing an alternative to personal phones, such as a key or a company-supplied device, is fair and avoids disputes about reimbursement or privacy.
Start with the leadership team and IT. They find problems, and leaders who live with the change themselves explain it better. Then add one department, perhaps business office staff, before touching clinical units.
Explain why in a sentence or two. "Attackers regularly steal passwords. This extra step stops them even when they have yours." Give a one-page how-to with screenshots, and hold short drop-in sessions on each shift, including nights and weekends.
Think through these before they happen:
A staff member loses or replaces a phone. Who verifies identity and resets MFA, and how?
A person works nights, when the help desk is slow to answer. Is there after-hours support?
A shared workstation is used by several people in a shift. How do they sign in quickly without bypassing protection?
A phone has no signal in some parts of the building. Is there an offline option?
Track how many people are enrolled, how many help requests come in, and where friction occurs. Reduce prompts where it is safe, for example by allowing a trusted device to stay signed in for a limited time, and keep strict prompts for new locations or administrator actions.
Turning it on for everyone on a Friday afternoon
Skipping recovery procedures, so lockouts become emergencies
Exempting executives or administrators, who are prime targets
Leaving old logins that bypass MFA, such as legacy email protocols
Treating enrollment as one-time and forgetting new hires
MFA is not a cure-all. Attackers sometimes trick users into approving a prompt, so training still matters, but it is a major improvement over passwords alone, and cyber insurance applications increasingly ask about it.
UnityCare IT plans and supports MFA rollouts for healthcare organizations, including shared-workstation scenarios and after-hours support. If you want a rollout your staff will tolerate, and even appreciate, we can help map out the steps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172