Two-Factor Authentication (TOTP) for Staff
Two-factor authentication (TOTP) adds a second step to sign-in: a 6-digit code from an authenticator app on your phone, in addition to your normal sign-in. Hospital admins, feedback managers, and clinical staff reviewers must enroll before they can use the app; dietary staff can enroll voluntarily.
Enroll in two-factor authentication
- Sign in and open the Account page.
- Under Multi-factor auth, select Enroll.
- Scan the QR code shown on screen with an authenticator app — Google Authenticator, Authy, 1Password, or any other TOTP app — or enter the displayed secret manually if you can’t scan a code.
- Save the 10 backup codes shown on screen somewhere safe; each one works once if you ever lose access to your authenticator app.
- Check “I have saved my backup codes,” enter the 6-digit code from your app, and select Confirm.
Sign in with two-factor authentication
Once you’re enrolled, every sign-in asks for a fresh 6-digit code from your app (or one of your backup codes if your phone isn’t available) before your session opens. If you sign in through your hospital’s own identity system (EHR single sign-on), that sign-in satisfies this requirement automatically and you won’t be asked for a separate code.
If you lose your device
A hospital administrator can reset your two-factor authentication — for example after a lost phone — by selecting Reset MFA on the User management page. This signs you out everywhere, and you’ll need to set up two-factor authentication again the next time you sign in.