MFA Everywhere: The Cheapest Protection Your Clinic Can Turn On

One stolen password is all it takes — unless a second check stops it. Multi-factor authentication costs nothing, takes an afternoon, and blocks the most common way attackers get in.

Dental hygienist with a patient — protecting health data in daily care

What MFA is, in one paragraph

Multi-factor authentication means proving who you are two ways instead of one. The password is the first way — something you know. The second way is something you have: a code from an app on your phone, a tap on a prompt, a fingerprint. A stolen password alone no longer gets an attacker in.

This matters because passwords get stolen constantly — phishing emails, reused passwords from breached websites, sticky notes under keyboards. MFA is the control that makes a stolen password useless. It costs nothing, takes an afternoon to roll out, and stops the single most common way attackers get into small businesses.

Where to enable it first

You do not have to do everything on day one. Turn it on in this order:

  • Email first. Your email is the keys to the kingdom — password resets for everything else flow through it. If only one system gets MFA this week, this is the one.
  • Your EHR and practice management system. Direct access to patient records. Most modern EHRs support MFA; if yours does not, that is a question for your vendor.
  • Remote access and VPN. Anything reachable from outside the building is reachable by attackers too. Remote access without MFA is an open door.
  • Admin and owner accounts. The accounts with the most power get protected first — including yours.
  • Everything else, working down the list. Billing software, cloud storage, the appointment reminder system. If it holds patient data or touches money, it gets MFA.

Handling shared workstations without losing your mind

The objection every clinic raises: “But six people share the front-desk computer.” Fair. Here is how it works in practice:

Individual logins, not one shared account. Each person logs in as themselves — Windows and most EHRs support fast user switching, which takes seconds. Shared accounts also violate HIPAA’s requirement for unique user identification, so this fixes two problems.

MFA per person, not per computer. Each employee enrolls their own phone once. After that, approving a login is one tap. It adds about five seconds to a login.

For staff without smartphones — rare, but it happens — hardware security keys cost little and plug into USB. One key per person, no phone required.

Set session timeouts sensibly. Short enough that a walked-away workstation locks itself, long enough that staff are not logging in forty times a day. Fifteen minutes is the usual starting point; adjust from there.

When someone loses their phone

It will happen — a phone with the authenticator app ends up in a parking lot. The recovery process should be boring: the employee tells the office manager, IT revokes the MFA enrollment for the lost device, and the employee re-enrolls the replacement. Two things make this painless instead of panicked. First, keep a short list of who to call — your IT provider’s after-hours number posted where staff can find it beats a frantic search at 9 p.m. Second, enroll a backup method for key accounts — a second device or printed backup codes stored in a locked drawer — so one lost phone does not lock anyone out of email on a Monday morning. Practice it once with your own phone so the process is familiar before it matters.

For the front desk specifically, prefer tap-to-approve prompts over typed codes — one tap is faster than reading six digits, and speed is what keeps staff from resenting the control.

What to do Monday morning

Turn on MFA for your own email account today — yours, personally, before anyone else’s. Then have your IT provider pull the list of which systems support MFA and which do not. The “do not” list becomes your vendor conversation list. One afternoon, biggest security win on the board.

And while you are at it, confirm that former employees’ MFA enrollments were actually removed — a disabled password with an active authenticator enrollment is a half-closed door. Access reviews twice a year catch exactly this. Roll it out team by team rather than all at once — owners and admins this week, clinical staff next, front desk last with the most hands-on help. Each group’s questions make the next group’s rollout smoother.

Not sure where your practice stands?

Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

Will MFA slow down our front desk?

Barely. After the one-time enrollment, logging in adds one tap on a phone — about five seconds. Clinics that switch report the complaints last about a week and then nobody thinks about it.

What if an employee does not have a smartphone?

Use a hardware security key — a small USB device, one per person, no phone needed. They are inexpensive and work with most systems that support MFA.

Does MFA replace the need for strong passwords?

No — it adds to them. MFA plus a unique password per person is the combination. MFA without decent passwords, or passwords without MFA, each leave a gap.

Our EHR does not offer MFA. What do we do?

Ask the vendor when it is coming, in writing. In the meantime, protect everything around it — email, remote access, and the workstations themselves — and make the vendor’s answer part of your risk assessment.

Is text-message MFA good enough?

It is far better than nothing, and for most small clinics it is a fine starting point. App-based codes or prompts are stronger because text messages can be intercepted — upgrade when you can, but do not let perfect block you from starting.