Multi-Factor Authentication: Supported Use Cases

Overview

Thyra EHR supports authentication of a user's identity through multiple elements using an industry-recognized standard. This page describes the supported multi-factor authentication (MFA) use cases.

Standard used

Time-based One-Time Password (TOTP) per RFC 6238 (OATH), used as a second authentication factor in addition to the user's password.

Supported use cases

  1. Enrollment | enroll a TOTP authenticator app by scanning a QR code and verifying a one-time code; one-time-view recovery codes are issued.
  2. Authenticated sign-in | after username/password, provide a current TOTP code to complete authentication.
  3. Recovery | if the authenticator is unavailable, complete sign-in with a one-time recovery code; recovery-on-disable governs re-enrollment.
  4. Administrative policy | administrators can require MFA for specified users/roles.
  5. Account protection | repeated failed attempts trigger a database-backed distributed account lockout.

Applicability

MFA protects user access to electronic health information and applies to the accounts for which the organization enables it. Controlled-substance e-prescribing additionally uses two-factor authentication at signing through the relied-upon e-prescribing service.