Rolling Out Multifactor Authentication Without Staff Revolt

Multifactor authentication, often shortened to MFA, asks for something beyond a password, usually a code or approval from a phone or a hardware key. It is one of the most effective protections available because a stolen password alone no longer opens the door. It is also one of the protections care teams complain about most when it is rolled out badly.

The difference between a smooth rollout and a rebellion is almost always planning. Here is a sequence that works in facilities with shift staff, shared workstations and mixed technical comfort.

Step 1: Decide What to Protect First

You do not have to cover everything on day one. Prioritize in this order:

Email, since a compromised mailbox is the starting point for many incidents

Remote access, including VPN and remote desktop

Administrator and IT accounts

Cloud applications that contain resident or financial information

Your EHR or electronic health record portal, where the vendor supports it

Many vendors, including major EHR platforms, offer their own MFA options. Ask your vendor what is available.

Step 2: Choose Methods That Fit the Workforce

Not every employee has a smartphone they want to use for work, and some units restrict phones near residents or during care.

Authenticator apps

Push approval or number-matching apps are secure and convenient for staff with smartphones. Number matching, where the user types a number shown on the login screen, reduces accidental approvals.

Hardware keys or badges

For shared workstations, a physical key or badge tap can be faster than typing codes, and does not require a personal phone.

Text messages

Better than nothing, but easier to attack. Use only where nothing else is workable.

Providing an alternative to personal phones, such as a key or a company-supplied device, is fair and avoids disputes about reimbursement or privacy.

Step 3: Pilot With a Friendly Group

Start with the leadership team and IT. They find problems, and leaders who live with the change themselves explain it better. Then add one department, perhaps business office staff, before touching clinical units.

Step 4: Communicate in Plain Language

Explain why in a sentence or two. "Attackers regularly steal passwords. This extra step stops them even when they have yours." Give a one-page how-to with screenshots, and hold short drop-in sessions on each shift, including nights and weekends.

Step 5: Plan for the Exceptions

Think through these before they happen:

A staff member loses or replaces a phone. Who verifies identity and resets MFA, and how?

A person works nights, when the help desk is slow to answer. Is there after-hours support?

A shared workstation is used by several people in a shift. How do they sign in quickly without bypassing protection?

A phone has no signal in some parts of the building. Is there an offline option?

Step 6: Watch and Adjust

Track how many people are enrolled, how many help requests come in, and where friction occurs. Reduce prompts where it is safe, for example by allowing a trusted device to stay signed in for a limited time, and keep strict prompts for new locations or administrator actions.

Mistakes to Avoid

Turning it on for everyone on a Friday afternoon

Skipping recovery procedures, so lockouts become emergencies

Exempting executives or administrators, who are prime targets

Leaving old logins that bypass MFA, such as legacy email protocols

Treating enrollment as one-time and forgetting new hires

Beyond Passwords

MFA is not a cure-all. Attackers sometimes trick users into approving a prompt, so training still matters, but it is a major improvement over passwords alone, and cyber insurance applications increasingly ask about it.

Working With UnityCare IT

UnityCare IT plans and supports MFA rollouts for healthcare organizations, including shared-workstation scenarios and after-hours support. If you want a rollout your staff will tolerate, and even appreciate, we can help map out the steps.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172