AdministrationSystem AdminMFA Configuration
Authentication Methods3 of 3 methods enabled
TOTP
Authenticator app (Google Authenticator, Authy, 1Password)
34 users enrolled
Token validity: 30 seconds
Algorithm: HMAC-SHA1
SMS
One-time code sent via text message to registered phone
8 users enrolled
Code expiry: 10 minutes
Provider: Twilio
Email OTP
One-time code sent to user's registered email address
5 users enrolled
Code expiry: 15 minutes
Provider: SendGrid
Enforcement Policy
MFA Enforcement
Require MFA for all logins system-wide
Grace Period (new users)
Days before MFA is required for new accounts
Remember Device
Days before re-authentication required
Failed Attempts Lockout
Lock account after N failed MFA attempts
Recovery CodesEnabled

Recovery codes allow users to bypass MFA in case they lose access to their authentication device. Each code can only be used once.

Codes per user
Alert on use
Notify admin when recovery code is used
Force reset after use
Require MFA re-enrollment after recovery
User MFA Status
3 users without MFA
UserRoleMFA MethodEnrolled DateLast UsedStatusActions
Sarah ChenClinical AdminTOTPJan 10, 2026Today 9:14 AMActive
James ParkSuper AdminTOTPDec 1, 2025Today 8:02 AMActive
Maria TorresBilling AdminSMSFeb 3, 2026YesterdayActive
Dr. Robert LeeProviderEmail OTPMar 15, 2026Apr 1Active
Tom WilsonRead OnlyNot Enrolled
Brian NguyenRead OnlyNot Enrolled
Nancy RiveraClinical AdminPending Setup
Linda KimCare ManagerTOTPJan 20, 2026Apr 1Active
SAML / SSO ConfigurationNot Configured

SAML 2.0 SSO is not currently enabled. Configure your Identity Provider below to allow single sign-on via Okta, Azure AD, or ADFS.

AI Assistant

MFA Configuration controls how users authenticate. HIPAA compliance requires strong authentication for PHI access.

  • TOTP is the most secure option
  • SMS is convenient but less secure (SIM swap risk)
  • Email OTP is the fallback method
  • Users can only have one method active at a time

SSO delegates authentication to your corporate Identity Provider. When SSO is active, the IDP's MFA policies apply. Local MFA methods are bypassed for SSO users.

Each recovery code use is logged in HIPAA audit logs. Users should store codes in a secure location. Admin notification on use helps detect unauthorized access.

Save MFA Settings

Changes will apply to all users immediately. MFA enforcement, grace periods, and device trust settings will be updated.

Enforce MFA for All Users

This will require all users to set up MFA on their next login. Users without MFA will be locked out until they enroll.

Regenerate Recovery Codes

This will invalidate all existing recovery codes for every user. Users will need to save new codes on their next login.

Export MFA Report

Notify Non-Enrolled Users

3 users are not enrolled in MFA. An email will be sent with enrollment instructions.

Reset User MFA

This will remove the current MFA enrollment for . They will be required to set up MFA again on next login.

Send MFA Enrollment

An enrollment email will be sent to with instructions to set up MFA.

Toggle MFA Method

Test SAML Connection

This will attempt to validate the SAML configuration by connecting to your Identity Provider.

Save SSO Configuration

Saving SSO configuration will enable SAML authentication. It is strongly recommended to test the connection first.