Secure your account with two-factor authentication
Published · Last updated
Why turn it on
Two-factor authentication (2FA) adds a second step when you sign in: your password plus a
one-time code from an app on your phone. Even if someone learns your password, they can't get in
without your phone. On a product that holds client health information, it's the single best thing
you can do to protect your account.
Turn on two-factor authentication
- Go to Two-factor authentication in your account settings.
- Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, or
similar). - Enter the 6-digit code the app shows to confirm it's linked.
- Save your backup codes. You'll be shown a set of one-time backup codes — store them
somewhere safe (a password manager). They're how you get in if you lose your phone.
Signing in with 2FA
After it's on, each sign-in asks for a code from your authenticator app after your password. If
you don't have your phone, use one of your backup codes instead — each code works once.
Who can do this
Anyone can turn on two-factor authentication for their own login — it protects your account
and follows you across every practice you belong to. It's a per-user setting, so turning it on
doesn't change anything for your teammates.
Tips
- Treat backup codes like spare keys: save them before you leave the setup screen, and regenerate
them if you ever think they've been exposed. - If you get a new phone, set up your authenticator app there before wiping the old one, or keep
your backup codes handy.