Secure your account with two-factor authentication

Published · Last updated

Why turn it on

Two-factor authentication (2FA) adds a second step when you sign in: your password plus a
one-time code from an app on your phone. Even if someone learns your password, they can't get in
without your phone. On a product that holds client health information, it's the single best thing
you can do to protect your account.

Turn on two-factor authentication

  1. Go to Two-factor authentication in your account settings.
  2. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, or
    similar).
  3. Enter the 6-digit code the app shows to confirm it's linked.
  4. Save your backup codes. You'll be shown a set of one-time backup codes — store them
    somewhere safe (a password manager). They're how you get in if you lose your phone.

Signing in with 2FA

After it's on, each sign-in asks for a code from your authenticator app after your password. If
you don't have your phone, use one of your backup codes instead — each code works once.

Who can do this

Anyone can turn on two-factor authentication for their own login — it protects your account
and follows you across every practice you belong to. It's a per-user setting, so turning it on
doesn't change anything for your teammates.

Tips

  • Treat backup codes like spare keys: save them before you leave the setup screen, and regenerate
    them if you ever think they've been exposed.
  • If you get a new phone, set up your authenticator app there before wiping the old one, or keep
    your backup codes handy.