Back to resources

Multi-factor authentication (MFA) is the single most effective control you can add to a small practice's security posture. It stops the majority of account takeover attacks cold, it's free on almost every major platform, and it takes about ten minutes to set up. And yet most small practices still don't have it enabled on the accounts that matter most.

Here's what it is, why it works, and how to turn it on.

What multi-factor authentication is

When you log in with just a password, you're using one factor: something you know. Multi-factor authentication requires a second factor: something you have (a phone, a hardware key) or something you are (a fingerprint, a face scan).

The most common form you'll encounter is a six-digit code that gets sent to your phone or generated by an app. You enter your password, then you enter the code. Even if someone steals your password, they can't log in without the second factor.

MFA stops 99% of automated account takeover attacks according to Microsoft's security research. Passwords get stolen constantly through data breaches, phishing, and credential stuffing. MFA makes stolen passwords nearly worthless.

Where to enable it first

Start with the accounts where a breach would do the most damage. For a small practice, that's typically:

Types of MFA and which to use

Not all MFA is equally strong. From weakest to strongest:

How to enable it on major platforms

Google Workspace / Gmail

Go to myaccount.google.com > Security > 2-Step Verification. As an admin, you can require MFA for all users in your workspace through the Admin Console under Security > Authentication > 2-step verification.

Microsoft 365 / Outlook

Go to admin.microsoft.com > Settings > Org settings > Security and privacy > Multi-factor authentication. Enable security defaults, which turns on MFA for all users. Or use Conditional Access policies for more granular control.

Individual accounts

For any platform, look for "Security" or "Account settings" and search for "two-factor," "MFA," or "two-step verification." Almost every major platform supports it.

Handling staff resistance

The most common objection: "It's one more step every time I log in." That's true, but modern authenticator apps make the friction minimal. After the first few days, it becomes automatic. The alternative, explaining to patients why their data was compromised, is considerably more friction.

If you're requiring MFA for staff, give them a 30-minute setup session, walk them through installing an authenticator app, and test that it works before they leave. The first setup is the hardest part.


MFA is the fastest security improvement available to a small practice. Enable it on email today. Expand to other accounts this week. It takes an afternoon and it addresses one of the most common breach pathways in a single step.

Want to know which of your accounts are most at risk?

The free Cyber Health Score takes 5 minutes and flags authentication gaps across the tools your practice uses.

Get your free Cyber Health Score