Multi-factor authentication stops the vast majority of account takeovers, which makes it one of the best security investments a facility can make. It is also the change staff push back on hardest, because anything that adds a step at the keyboard feels like friction during a busy shift. Both things are true, and both can be managed.
Why MFA matters so much
Passwords get reused, phished, and guessed. MFA means that even a stolen password is not enough to get in. For email, remote access, and the EHR, that single control blocks attacks that would otherwise succeed.
Rolling it out without the revolt
- Start with the highest-risk accounts: email, remote access, and administrators.
- Choose methods that fit the workflow, like app prompts or badges, not clumsy code entry on shared devices.
- Use trusted devices and sensible session lengths so staff are not prompted constantly.
- Explain the why in plain terms: it protects residents, and it protects them personally.
- Roll out in stages, with support on hand, rather than flipping a switch overnight.
Resistance to MFA is almost always about how it was deployed, not about MFA itself. Thoughtful rollout turns a source of complaints into a control nobody thinks about.
The insurance angle
Cyber-insurance carriers increasingly require MFA to issue or renew a policy. Putting it in place is no longer just good practice. It is often the difference between being insurable and not.