MFA Configuration controls how users authenticate. HIPAA compliance requires strong authentication for PHI access.
MFA Configuration
Configure multi-factor authentication methods and enforcement policies
Authentication Methods3 of 3 methods enabled
TOTP
Authenticator app (Google Authenticator, Authy, 1Password)
34 users enrolled
Token validity: 30 seconds
Algorithm: HMAC-SHA1
SMS
One-time code sent via text message to registered phone
8 users enrolled
Code expiry: 10 minutes
Provider: Twilio
Email OTP
One-time code sent to user's registered email address
5 users enrolled
Code expiry: 15 minutes
Provider: SendGrid
Enforcement Policy
MFA Enforcement
Require MFA for all logins system-wide
Grace Period (new users)
Days before MFA is required for new accounts
Remember Device
Days before re-authentication required
Failed Attempts Lockout
Lock account after N failed MFA attempts
Recovery CodesEnabled
Recovery codes allow users to bypass MFA in case they lose access to their authentication device. Each code can only be used once.
Codes per user
Alert on use
Notify admin when recovery code is used
Force reset after use
Require MFA re-enrollment after recovery
User MFA Status
3 users without MFA
| User | Role | MFA Method | Enrolled Date | Last Used | Status | Actions |
|---|---|---|---|---|---|---|
| Sarah Chen | Clinical Admin | TOTP | Jan 10, 2026 | Today 9:14 AM | Active | |
| James Park | Super Admin | TOTP | Dec 1, 2025 | Today 8:02 AM | Active | |
| Maria Torres | Billing Admin | SMS | Feb 3, 2026 | Yesterday | Active | |
| Dr. Robert Lee | Provider | Email OTP | Mar 15, 2026 | Apr 1 | Active | |
| Tom Wilson | Read Only | — | — | — | Not Enrolled | |
| Brian Nguyen | Read Only | — | — | — | Not Enrolled | |
| Nancy Rivera | Clinical Admin | — | — | — | Pending Setup | |
| Linda Kim | Care Manager | TOTP | Jan 20, 2026 | Apr 1 | Active |
SAML / SSO ConfigurationNot Configured
SAML 2.0 SSO is not currently enabled. Configure your Identity Provider below to allow single sign-on via Okta, Azure AD, or ADFS.