Getting Started

Setting Up and Using Two-Factor Authentication (2FA)

2FA adds a second verification step after the password/OTP login, protecting accounts (especially clinicians and admins with access to sensitive patient data) even if a password is compromised.

Setting up 2FA

  1. Go to 2FA Setup (?page=2fa-setup) — usually prompted automatically the first time an admin enforces 2FA, or accessible from your profile.
  2. Scan the QR code with an authenticator app (Google Authenticator, Authy, etc.) or enter the provided secret key manually.
  3. Enter the 6-digit code generated by the app to confirm setup.
  4. Save the backup/recovery codes shown — store them somewhere safe in case you lose access to the authenticator app.

Verifying with 2FA at login

  1. After entering your password/OTP, you'll land on the 2FA Verify screen (?page=2fa-verify).
  2. Enter the current 6-digit code from your authenticator app.
  3. If you've lost access to your device, use a backup recovery code instead.

Common issues & fixes

authenticator codes rotate every 30 seconds; make sure your phone's clock is in sync.
use a saved backup code, or ask an admin to reset 2FA on your account.
some clinics require 2FA for all users; you won't be able to skip setup on first login.

Was this article helpful?

Thanks for the feedback!
ESC
navigate open esc close