Multi-factor authentication (MFA)
To log in, some users will be required to complete an additional verification using a mobile phone to receive a code, which is then entered onscreen. Once a user has completed this step, he/she might not be asked to do this again for some time.
-
Benefits of MFA:
-
Better protects patient health information (PHI) and reduces the risk of unauthorized access.
-
Meets enterprise-level security standards and HIPAA best practices.
-
-
Only for unusual circumstances - Even if MFA is active, you might not be required to complete the MFA steps to log in. For most users, MFA will only be required when something unusual occurs—like logging in from a new device or location.
-
User account restrictions - MFA requires verification using a unique email address for each individual user. Therefore, MFA cannot be enabled for user accounts that share the same email address. To ensure that the user accounts in your organization are not prevented from having the higher level of security provided by MFA, make the following changes as needed to user accounts that are currently ineligible for MFA:
-
Email addresses - Resolve duplicate emails. Each user must have a unique email address.
-
Usernames - Change usernames that do not follow the naming convention that is required for MFA. Any user accounts with unapproved usernames will not be enrolled in MFA.
Important:
-
New accounts cannot be created using duplicate email addresses.
-
Editing an existing account with a duplicate email address will require updating it to a unique email address first.
-
-
Ineligible user accounts - Any user account that is ineligible for MFA is disabled, preventing the user from logging in to Dentrix Ascend. If your account is disabled, an error message appears when you attempt to log in. You must contact your organization's Dentrix Ascend administrator to correct the reason for your ineligibility.
-
MFA and better security - The following security practices for Dentrix Ascend should minimize the impact of MFA, reducing the instances of being asked to complete MFA:
-
Using a VPN - Using a VPN may trigger a request to complete MFA, especially when turning off/on could cause your location to appear as having changed from your previous login. In this scenario you should be prepared to receive an SMS code on a mobile device at your current location.
-
Consistent VPN usage - If possible, use a single, dedicated VPN location rather than switching, or disable the VPN when not necessary.
-
-
Avoid shared accounts - Using shared accounts (such as members of a team logging in using the same account) causes multiple, disparate locations to log in simultaneously, potentially triggering MFA requests.
-
Use known devices/networks - Log in from trusted devices, home Wi-Fi, or corporate, known IPs.
-
Proper logout/login procedure - If traveling, ensure a session is fully terminated in one location before starting a new one in another, allowing for realistic travel time.
-
Securely configure locations - If you are responsible for managing security, exclude trusted locations like corporate office IP addresses from detection policies.
-