If your practice runs on Microsoft 365, Google Workspace, or a cloud-based patient record system, the systems you already own almost certainly include multi-factor login. It is usually switched off by default. Multi-factor login means that after someone types the right password, they also have to confirm a code on a phone, so a stolen or guessed password alone can no longer open the door.
For a clinic with one to ten people, this is one of the highest-impact, lowest-effort things you can do. Most breach investigations at small practices trace back to a single reused or phished password. Turning on multi-factor login closes that path without new hardware, a consultant, or an IT department.
None of this requires you to be technical. It is a setting to enable and confirm across your email, your patient record system, and any remote-access tools. The goal is simply that every system holding patient information asks for that second confirmation.
What to check in your practice
- Confirm multi-factor login is turned on for your practice email (Microsoft 365 or Google Workspace admin settings).
- Confirm it is turned on for your patient record / EHR system: check the security or login settings, or ask your vendor.
- Turn it on for any remote-access or billing tools that can reach patient information.
- Write down the date you verified each one; that record is part of your documentation trail.