Settings — Security
Two controls that apply to everyone who signs in under your provider network: multi-factor authentication and timed logout.
Security is the settings tab where a Provider Network Admin turns on multi-factor authentication and sets how long an idle session survives. Both controls apply to every user who signs in under this provider network.
Both switches save the instant you change them. There is no Save button and no confirmation dialog. Turning on multi-factor authentication forces every provider, delegate and admin in the network through an enrolment screen on their next sign-in — tell them first.
Questions people ask about this page
Who exactly does this affect?
Everyone who signs in under this provider network — Provider Network Admins, Providers, and Provider Delegates. The card says it plainly: Controls apply to users logging in under this provider network. It does not reach your linked clients' staff or their patients; each client sets its own security on its own Settings page.
Can I require the authenticator app and not email codes?
No. The switch is one control and it enables both methods together. Each user then chooses on the enrolment screen: Email code or Authenticator app.
What does a user see the first time after I turn MFA on?
A blocking screen headed Set up 2-step verification, with the line {your network name} requires 2-step verification. Choose how you want to verify your sign-ins. They pick Email code (Get a 6-digit code at your account email address.) or Authenticator app (Use Google Authenticator, 1Password, Microsoft Authenticator, or a similar app.), enter the code, and click Finish setup.
A provider lost their phone and cannot get past verification.
On the Verify your sign-in screen they click Use email code instead and get a 6-digit code at their account email. During first-time enrolment the equivalent button is Choose a different method; from the email screen it is Use authenticator app instead. If they are still locked out, raise a ticket from Support. There is no admin-side MFA reset on this page — the only admin lever is turning the switch off for the whole network.
Does the inactivity timeout log people out while they are working?
No. The helper reads Activity in any open tab keeps the session active. A provider with the charting workspace open and in use is not timed out. It catches abandoned sessions on shared machines.
Where do I change my own password or add Google sign-in?
Not here. Click your name at the bottom of the left menu (Open account settings) to open Edit Account Information, which has Update Your Password and Sign-In Methods with an Add Method button for Email & Password and Google.
Can I force everyone to re-authenticate right now?
There is no sign-out-everyone button on this page. Setting an inactivity timeout is the closest control, and it only ends idle sessions.
Where to find it
Left menu → Settings → the Security card. Direct link: /settings/security. Visible to: Provider Network Admin only.
The card on the Settings index reads Security — Configure MFA requirements, inactivity timeouts, and account protection rules. Inside, one card titled Security with the subtitle Controls apply to users logging in under this provider network.
What is on this page
| What you see | What it does |
|---|---|
| Multi-factor authentication switch | Requires a second factor at sign-in for everyone in the network. Helper: Users set up and verify with an email code or an authenticator app. |
| Timed logout after inactivity dropdown | Ends an idle session after the chosen period. Helper: Activity in any open tab keeps the session active. |
| Back to settings (icon button, top left) | Returns to the eight-card Settings index. |
How to turn on multi-factor authentication
Warn the network first
Message your Providers, Provider Delegates and fellow admins. The next time they sign in they cannot reach any page until they enrol.
Open the page
Left menu → Settings → Security.
Flip the switch
Click Multi-factor authentication. It saves immediately and the toast reads Security settings updated. Both methods — email code and authenticator app — are enabled together.
Check one account
Sign in as a test user in a private window and confirm you get Set up 2-step verification, not an error.
What a user walks through
| Screen | What it says | What they do |
|---|---|---|
| Set up 2-step verification | {network name} requires 2-step verification. Choose how you want to verify your sign-ins. | Pick Email code or Authenticator app. |
| Check your email | Enter the 6-digit code we sent to finish setting up 2-step verification. | Click Send code, type the code into Email code, click Finish setup. |
| Set up your authenticator app | Scan the QR code, then enter the 6-digit code from your app. | Scan with their app, type the code into Authenticator code, click Finish setup. |
| Verify your sign-in | Enter the 6-digit code sent to your email address. or Enter the 6-digit code from your authenticator app. | Type the code and click Verify. This is every later sign-in. |
| We could not check verification | Please try again or sign out and come back when you are ready. | Click Try again. |
How to set the inactivity timeout
Open the dropdown
Click Timed logout after inactivity.
Pick a window
Choose Disabled, 15 minutes, 30 minutes, 1 hour, 2 hours, or 4 hours.
Nothing else
It saves on selection. The toast reads Security settings updated.
Match the window to how your team works. Clinics with shared workstations usually pick 15 minutes or 30 minutes. Providers charting long sync visits from a private machine are better served by 2 hours or 4 hours — activity in any open tab keeps the session alive, but a long video call with no clicks can look idle.
Every setting on this page
| Setting | What it controls | Options | Default |
|---|---|---|---|
| Multi-factor authentication | Whether users in this network must verify with a second factor at sign-in. Enabling it turns on both the email-code and authenticator-app methods; users choose per account. | On / Off | Off |
| Timed logout after inactivity | How long an idle session lasts before the user is signed out. | Disabled, 15 minutes, 30 minutes, 1 hour, 2 hours, 4 hours | Disabled |
That is the whole tab. There is no password-complexity rule, no IP allowlist, no SSO configuration, no session-revoke button, and no per-role exception list. If you need one of those, raise it from Support rather than looking for a hidden control.
What can go wrong
| What you see | Why | Fix |
|---|---|---|
| Unable to update security settings with the description Missing provider network record. | Your account is not resolving a provider network. | Sign out and back in. If it persists, raise a ticket from Support. |
| Unable to update security settings with Please try again. | The write failed. | Flip the control again. Reload the page first to confirm which state actually saved — the switch shows what is stored, not what you clicked. |
| Providers are locked out the morning after you enabled MFA. | They have to enrol before they can reach any page and nobody warned them. | Walk them through Set up 2-step verification. If a shift is at risk, turn the switch off, let them work, and re-enable it with notice. |
| A user says they are signed out constantly. | The inactivity window is short for how they work. | Raise the timeout, or set it to Disabled while you decide. |
| You changed the setting and a colleague still sees the old value. | They loaded the page before the change. | Ask them to reload. This page reads the stored network record on load. |
| MFA is on but a client's staff are not prompted. | This setting only covers users signing in under your provider network. | The client sets MFA on its own Settings → Security page. |
| Page not found — The page you’re looking for doesn’t exist or you don’t have access. | You are signed in as a Provider or Provider Delegate. Settings is not in their left menu and /settings/security does not resolve for them. | Sign in as a Provider Network Admin. There is no read-only view of this tab for other roles. |
Next
Was this helpful?
