Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) adds a second layer of protection to a user's account. After entering a password, the user is asked for a one-time code — either from an authenticator app or sent by text message. Even if someone gets hold of the password, they can't sign in without that second factor.
On CareLaunch, MFA is managed by administrators on a per-user basis. It is not something users turn on for themselves — an administrator enables it on a user's record, and the user then completes setup (for authenticator apps) the next time they sign in. This is especially recommended for administrators and providers who have access to patient data.
Enabling MFA for a User (Administrators)
- Go to Administration > Users and open the user you want to protect.
- In the Multi-Factor Authentication card, turn on the Multi-Factor Authentication switch ("Require this user to provide a secondary authentication method when signing in").
- Choose one or both MFA Type options:
- Authenticator App — the user sets up a TOTP authenticator app at next sign-in.
- SMS — the user receives one-time codes by text message.
- Save the user. If Authenticator App is selected, the user is prompted to set it up the next time they sign in.
To remove MFA from a user, or to change the MFA type, an administrator returns to the same card, turns the switch off (or adjusts the MFA Type), and saves. Users cannot disable their own MFA.
Authenticator App Setup (Users)
When an administrator has required an authenticator app, the user is taken to a Set Up Authenticator App screen the next time they sign in.
Authenticator apps generate a new 6-digit code every 30 seconds on the user's device. They work offline and are more secure than SMS codes. Any TOTP-compatible app works, including:
- Google Authenticator (iOS / Android)
- Microsoft Authenticator (iOS / Android)
- Authy (iOS / Android / Desktop)
- 1Password
- Any other TOTP-compatible authenticator app
To complete setup:
- On the Set Up Authenticator App screen, open your authenticator app and choose Add account or the + icon.
- Scan the QR code shown on screen. If you can't scan it, use the "Can't scan?" setup key shown below the code to add the account manually.
- Your app starts generating 6-digit codes. Enter the current code in the 6-digit code field.
- Click Verify and enable. From now on, you'll be asked for a code from your authenticator app after entering your password.
If you need to stop and finish later, use Sign out on that screen; you'll be prompted again at your next sign-in.
SMS / Text Message
When an administrator has enabled SMS as the MFA type, a one-time code is sent by text message each time the user signs in. There is no separate self-service enrollment step — the user simply enters the code they receive at login.
Note: SMS delivery depends on the mobile carrier and network coverage. For uninterrupted access when travelling internationally or on an unreliable signal, an authenticator app is more reliable.
Signing In With MFA Enabled
- Enter your email and password on the login page as usual.
- You'll be taken to a verification screen asking for your code.
- Open your authenticator app (or check your text messages) for the current code.
- Enter the code and continue.
Codes from authenticator apps are time-sensitive — they refresh every 30 seconds. If a code doesn't work, wait for the next one and try again.
Lost Access to Your MFA Device
If you lose your phone or can no longer receive codes:
- Contact your organization administrator — they can turn off or reset MFA on your user record so you can sign in and set it up again.
- If you can't reach an administrator, contact [email protected] with your account email and be ready to verify your identity.
Frequently Asked Questions
Can I turn MFA on for myself? No — MFA is enabled by an administrator on your user record. If you'd like it enabled, ask your organization administrator.
Can I use any authenticator app? Yes — CareLaunch supports any TOTP-compatible authenticator app (Google Authenticator, Microsoft Authenticator, Authy, 1Password, and others).
Why isn't my code working? Make sure your device's clock is set to sync automatically. Authenticator apps rely on accurate time to generate valid codes. If the code still doesn't work, wait for the next one (codes refresh every 30 seconds).
I switched phones. How do I move my authenticator? Ask your administrator to reset MFA on your account. You'll be prompted to set up the authenticator app again on your new device at your next sign-in.
Need help? Reach out to us at [email protected].