Multi-Factor Authentication: Supported Use Cases
Overview
Thyra EHR supports authentication of a user's identity through multiple elements using an industry-recognized standard. This page describes the supported multi-factor authentication (MFA) use cases.
Standard used
Time-based One-Time Password (TOTP) per RFC 6238 (OATH), used as a second authentication factor in addition to the user's password.
Supported use cases
- Enrollment | enroll a TOTP authenticator app by scanning a QR code and verifying a one-time code; one-time-view recovery codes are issued.
- Authenticated sign-in | after username/password, provide a current TOTP code to complete authentication.
- Recovery | if the authenticator is unavailable, complete sign-in with a one-time recovery code; recovery-on-disable governs re-enrollment.
- Administrative policy | administrators can require MFA for specified users/roles.
- Account protection | repeated failed attempts trigger a database-backed distributed account lockout.
Applicability
MFA protects user access to electronic health information and applies to the accounts for which the organization enables it. Controlled-substance e-prescribing additionally uses two-factor authentication at signing through the relied-upon e-prescribing service.