Multi-factor authentication (MFA) is the single most effective control you can add to a small practice's security posture. It stops the majority of account takeover attacks cold, it's free on almost every major platform, and it takes about ten minutes to set up. And yet most small practices still don't have it enabled on the accounts that matter most.
Here's what it is, why it works, and how to turn it on.
What multi-factor authentication is
When you log in with just a password, you're using one factor: something you know. Multi-factor authentication requires a second factor: something you have (a phone, a hardware key) or something you are (a fingerprint, a face scan).
The most common form you'll encounter is a six-digit code that gets sent to your phone or generated by an app. You enter your password, then you enter the code. Even if someone steals your password, they can't log in without the second factor.
MFA stops 99% of automated account takeover attacks according to Microsoft's security research. Passwords get stolen constantly through data breaches, phishing, and credential stuffing. MFA makes stolen passwords nearly worthless.
Where to enable it first
Start with the accounts where a breach would do the most damage. For a small practice, that's typically:
- Email (Gmail, Outlook, Microsoft 365): Email is the master key to every other account. Password resets go to email. If your email is compromised, everything else is compromised. Enable MFA here first, before anywhere else.
- Your EHR or practice management system: This is where patient data lives. Check your vendor's security settings for MFA options.
- Cloud storage (Google Drive, Dropbox, OneDrive): If patient files or practice documents are stored here, MFA is essential.
- Billing and financial accounts: Any account connected to your bank or that can authorize payments.
- Remote access tools (VPN, Remote Desktop): If staff access the practice network remotely, this is a high-priority attack surface.
Types of MFA and which to use
Not all MFA is equally strong. From weakest to strongest:
- SMS codes (text message): Convenient and widely supported. Vulnerable to SIM-swapping attacks, but still far better than no MFA. Use this if it's the only option.
- Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy): Generates codes locally on your phone. More secure than SMS because it doesn't depend on your phone number. This is the best option for most small practices.
- Hardware keys (YubiKey): A physical device that plugs into your computer. Very secure, used primarily for high-risk accounts. Overkill for most small practice uses, but worth considering for admin accounts.
How to enable it on major platforms
Google Workspace / Gmail
Go to myaccount.google.com > Security > 2-Step Verification. As an admin, you can require MFA for all users in your workspace through the Admin Console under Security > Authentication > 2-step verification.
Microsoft 365 / Outlook
Go to admin.microsoft.com > Settings > Org settings > Security and privacy > Multi-factor authentication. Enable security defaults, which turns on MFA for all users. Or use Conditional Access policies for more granular control.
Individual accounts
For any platform, look for "Security" or "Account settings" and search for "two-factor," "MFA," or "two-step verification." Almost every major platform supports it.
Handling staff resistance
The most common objection: "It's one more step every time I log in." That's true, but modern authenticator apps make the friction minimal. After the first few days, it becomes automatic. The alternative, explaining to patients why their data was compromised, is considerably more friction.
If you're requiring MFA for staff, give them a 30-minute setup session, walk them through installing an authenticator app, and test that it works before they leave. The first setup is the hardest part.
MFA is the fastest security improvement available to a small practice. Enable it on email today. Expand to other accounts this week. It takes an afternoon and it addresses one of the most common breach pathways in a single step.
Want to know which of your accounts are most at risk?
The free Cyber Health Score takes 5 minutes and flags authentication gaps across the tools your practice uses.
Get your free Cyber Health Score