SupportSettings & Security

How to Enable Two-Factor Authentication

4 min read
Last updated: February 26, 2026

How to Enable Two-Factor Authentication

Two-factor authentication (2FA) adds an extra layer of security by requiring a second verification step when logging in.

Setting Up 2FA for Your Account

  • Go to Profile → Security (click your avatar in the top right, then Security)
  • Find the Two-Factor Authentication section
  • Click Enable 2FA
  • Choose your method:
  • Authenticator App (Recommended)

  • Download an authenticator app (Google Authenticator, Authy, or Microsoft Authenticator)
  • Scan the QR code displayed on screen with your authenticator app
  • Enter the 6-digit code from the app to verify
  • Save your backup codes in a secure location — these let you log in if you lose access to your authenticator app
  • SMS Verification

  • Confirm your phone number
  • Enter the verification code sent via SMS
  • Save your backup codes
  • Logging In with 2FA

    After entering your email and password:

  • You will be prompted for a verification code
  • Open your authenticator app and enter the current 6-digit code
  • Optionally check Remember this device for 30 days to skip 2FA on trusted devices
  • Requiring 2FA for All Staff

    Clinic owners can enforce 2FA for all team members:

  • Go to Settings → Security
  • Toggle Require 2FA for all users
  • Staff members will be prompted to set up 2FA on their next login
  • Users who do not complete setup within 7 days will be unable to log in until they do
  • Managing Backup Codes

  • Each setup generates 10 single-use backup codes
  • Use a backup code instead of the authenticator code if you lose your device
  • To generate new backup codes: Profile → Security → Regenerate Backup Codes
  • Old codes are invalidated when new ones are generated
  • Disabling 2FA

  • Go to Profile → Security
  • Click Disable 2FA
  • Enter your password to confirm
  • 2FA is removed from your account
  • Note: If the clinic requires 2FA for all users, individual users cannot disable it.

    For password management, see How to Change Your Password. For team security, see User Management.

    Still need help?

    Our support team is available Monday-Friday, 9am-6pm WAT.