Why add a second step

A password can be guessed, reused, or leaked. Two-factor authentication means a stolen password alone isn't enough to get into your account — you also need a code from an authenticator app on your phone.

Set it up

When prompted, scan the code shown with an authenticator app on your phone, then enter the 6-digit code it generates to confirm the two are linked.

The two-factor authentication setup screen with a scannable code and a field to confirm the generated code.
Scanning the setup code with an authenticator app.

Save your backup codes

Right after you enable two-factor authentication, you're shown a set of one-time backup codes. Save them somewhere safe — each one works once to get you signed in if you ever lose access to your authenticator app, and they're only shown this one time.

A grid of one-time backup codes shown after two-factor authentication is enabled.
The one-time backup codes shown right after enabling two-factor authentication.
They won't be shown again Store your backup codes somewhere you'll actually find them later — a password manager, not a sticky note. If you use them all, generate a fresh set from your two-factor settings.

Signing in afterwards

From now on, after your password you'll be asked for the current code from your authenticator app. Turn on Remember this device for 30 days on a device you trust and use often, so you're not asked for a code every single time you sign in there.

The two-factor code entry screen with a remember-this-device option for 30 days.
Entering a code with the remember-this-device option.

If you can't access your authenticator app

Use one of your backup codes to sign in instead of a code from your app. If you've used them all or never saved them, contact your clinic's administrator, or support if you administer the account yourself, to have it reset.

Was this article helpful?
Your feedback helps us improve our documentation.
Rate this article: