Multi-Factor Authentication (MFA) adds an additional step for verification during sign-in, increasing security for your clinic. After MFA is enabled for a clinic, users must verify their selected MFA method before MFA is fully active for their account.
Enabling Multi-Factor Authentication for your Clinic
First, go to Settings, then Practice Details. Under the Basics tab, scroll down to Security and enable Multi-Factor Authentication (MFA).

Next you will be prompted to Set Up MFA. You can select either SMS (Recommended) or Email.

Note: If Email is selected, only the clinic admin will be able to reset your password.
Once you make your selection, select Send Verification Code and you will receive a generated code through the contact method of choice as indicated by the notification in the upper right. Once you receive the code, enter it in the box provided and select Verify.

If you type in the wrong code, an error message will appear in the upper right.

Once you have entered the correct code, a message will appear in the upper right indicating that MFA setup is complete.

By selecting Details under the Multi-Factor Authentication (MFA) section, you can see which accounts are verified and the type of MFA that is enabled.

After signing and out and signing back in using MFA, the account will show as verified.

Changing the MFA method for Existing Users
You can change the MFA method for existing users by going to User Access under Settings, selecting an account, and then selecting Edit.

Under MFA Method select either SMS or Email, re-enter the user's password, and select Save User.

Once the user has been saved, that user will be prompted to enter an MFA code through the Set Up MFA menu. They can select either SMS or Email from here.

Once they have entered an MFA code, they will appear as verified.

Resetting Passwords with MFA Enabled
To begin, select Forgot your password? at the bottom of the login screen.

After entering your username, you will receive an MFA code via the method selected during account/MFA setup. Enter that into the Code box along with your new password and select Submit. If you need a new code, select Resend Code at the bottom.

Note: If Email is selected as the MFA method, only the clinic admin will be able to reset your password.
Creating a New User with MFA Enabled
Begin by creating a new user under User Access in the Settings menu. In the Create User window, enter the user's information, select the MFA Method type, enter the user's Password and Re-Enter their Password, and then select Save User.

After setting up the new user, they will not automatically be verified and will need to log in using MFA at least once. You can see this in the Multi-Factor Authentication (MFA) section in Settings. There will be a notification that Some therapists are still pending verification.


When the new user logs in for the first time they will be greeted with the Set Up MFA menu where they can choose their desired method for MFA and confirm a code. Then they will be verified in the system.

The next time this user signs in they will need to verify their account using MFA to log in.
If they select cancel, they can temporarily mute this notification for 24 hours to delay setting up MFA.

Logging in Using MFA
When you log in with MFA enabled, you will enter your username and password as normal, then a code will be generated and sent to you using the MFA method selected during setup. Once you receive the code, enter it into the following menu:

Once you have your account set up, you can select Remember this device to reduce security prompts to bypass MFA on the same device for future log ins.

MFA for Legacy Users
Accounts using our old MFA method will be able to use the new MFA system as soon as they log in. After successfully logging in you will be greeted by the Set Up MFA menu. Simply choose your MFA method and select Send Verification Code as instructed. Then enter the code once it is received.

You will see verification that MFA has been set up successfully in the top right of the screen.
