Settings — Security
One switch: require 2-step verification for everyone who signs in under your client account, patients included.
This settings tab has one control: whether everyone who signs in under your client account must complete 2-step verification.
Questions people ask about this page
Does this apply to my patients as well as my staff?
Yes. "Users logging in under this client" means Client Admin, Client Staff, and every Patient on your account. Turning this on puts a mandatory 2-step verification setup screen in front of your patients the next time they sign in. Do not turn it on casually on a live consumer brand.
What exactly does a user have to do once I turn it on?
At their next sign-in they see a full-screen card headed Set up 2-step verification with two choices: Email code ("Get a 6-digit code at your account email address") or Authenticator app ("Use Google Authenticator, 1Password, Microsoft Authenticator, or a similar app"). They finish once, and from then on they are asked for a 6-digit code each new sign-in session.
Can I turn it on for staff but not patients?
No. There is one switch and it covers every role that signs in under your client. There is no per-role or per-user exception.
Where do I set a session timeout or a password policy?
Neither exists for a client account. A timed logout after inactivity is built into the shared security component but is not shown on the client tab, and there is no password-length, rotation, or IP-allowlist control anywhere. Individual passwords and sign-in methods are managed per user under Account settings in the sidebar.
I thought this tab also had my domain settings.
It used to be described that way. Your portal URL, custom domain, and email sending domain are on Settings → Branding. See Branding, URL, and custom domain.
What if a user loses their authenticator app?
On the verification screen they can click Use email code instead, which sends a 6-digit code to their account email address. If they have also lost access to that email, open a support ticket — there is no self-service reset on this tab.
Is turning it off retroactive?
Turning the switch off stops the app asking for a code. Enrolments already completed are kept, so turning it back on later does not force everyone to re-enrol.
Where to find it
Left menu → Settings → the Security card. Direct link: /settings/security. Visible to: Client Admin only. This tab exists on every client model, including Review Only.
What is on this page
| What you see | What it does |
|---|---|
| Page heading Security | Sub-line reads "Configure MFA requirements for users logging in under this client." |
| Card Security | Sub-text: "Controls apply to users logging in under this client." |
| Row Multi-factor authentication | Helper: "Users set up and verify with an email code or an authenticator app." The switch is the only control on the tab. |
There is nothing else on this page. No cards below, no advanced section, no save button — the switch writes immediately.
How to require 2-step verification
Tell your team first
Turning this on interrupts the next sign-in for every user under your account, patients included. Send the heads-up before you flip the switch, not after.
Open the tab
In the left menu, click Settings. On the Account settings grid, click the Security card.
Turn on the switch
Click the switch beside Multi-factor authentication. Its label for screen readers is Toggle multi-factor authentication.
Confirm it saved
A toast reads Security settings updated. If it reads Unable to update security settings, the write failed — try again and check the description line for the reason.
Verify with one account
Sign out and back in as a test user. You should see the Set up 2-step verification card before any app page renders.
What your users go through
They choose a method
The card reads "{Your brand} requires 2-step verification. Choose how you want to verify your sign-ins." with two options: Email code and Authenticator app.
Email code path
The screen changes to Check your email with a Send code button. A toast confirms Verification code sent. They type the 6 digits into the Email code field (placeholder 000000) and submit.
Authenticator path
The screen changes to Set up your authenticator app and shows a QR code plus the secret in text. They scan it, type the 6 digits into Authenticator code, and click Finish setup.
Done
A toast reads 2-step verification is set up and the app loads. On later sign-ins the header reads Verify your sign-in and they enter a code only.
If they get stuck
Every screen has a way out: Choose a different method during setup, Use email code instead during verification, and a sign-out control on the card itself.
Every setting on this page
| Setting | What it controls | Default |
|---|---|---|
| Multi-factor authentication (switch) | When on, every Client Admin, Client Staff, and Patient signing in under this client must complete 2-step verification. Both methods are allowed: an emailed 6-digit code, or a time-based code from an authenticator app. Saves the moment you click it. | Off |
That is the complete list. For comparison, the shared security component also supports a Timed logout after inactivity selector (Disabled, 15 minutes, 30 minutes, 1 hour, 2 hours, 4 hours), but the client view does not render it. Provider Network Admins do see it on their equivalent tab.
Security controls that live somewhere else
| What you are looking for | Where it is |
|---|---|
| Your own password and sign-in methods | Sidebar → Account settings → cards Update Your Password and Sign-In Methods. |
| Who is on your team, and deactivating someone | /dashboard → the Users card. See Your team and roles. |
| Custom portal domain, SSL, email sending domain | Settings → Branding. See Branding, URL, and custom domain. |
| API keys, allowed origins, webhook signing secrets | Settings → Developers. See Settings — Developers. |
| Terms, Privacy Policy, and BAA acceptance records | Settings → Account and billing → View agreements. |
| Who did what, and when | The Activity timeline. See Activity timeline. |
Statuses you will see here
This tab shows no status badges. The only feedback is a toast: Security settings updated on success, or Unable to update security settings with a reason on failure.
What can go wrong
| What you see | Why | Fix |
|---|---|---|
| Patients suddenly cannot sign in and are asked for a code | The switch applies to patients too, not just staff. | Turn it off if that was not intended, then plan a communication before turning it back on. |
| A user is stuck on Set up 2-step verification | They have not completed either method. The gate renders before any app page, so there is nothing else they can reach. | Walk them through the email-code path — it needs nothing installed. |
| "We could not check verification" | The app could not read your account's security policy, usually a transient network or permission problem. | Click Try again. If it persists, open a ticket. |
| A code is rejected | Authenticator codes rotate roughly every 30 seconds; emailed codes expire. | Request a fresh code and enter it promptly. All six digits are required before the submit button enables. |
| You expected a session-timeout control | It is not rendered for client accounts. | Nothing to configure. Tell staff to lock their machines. |
| You expected per-user MFA exemptions | The policy is account-wide. | Nothing to configure. |
| "Unable to update security settings" with "Missing client record." | Your session lost its link to the client account. | Reload the page and sign in again. |
Next
Was this helpful?
