Two-factor authentication (2FA, also called two-step verification) adds a second check when you
log in to Medic52: your password plus a 6-digit code from an authenticator app on your phone.
Even if someone learns your password, they cannot get into your account — or the patient
information it can reach — without your code. This article shows every Medic52 user how to turn
it on and how to keep the codes safe.
Before you begin
- You need an authenticator app on your phone. We recommend the free
Authy app. Google Authenticator and Microsoft Authenticator
also work — any standard authenticator app is fine. - Even better: most password managers can hold your 2FA codes alongside your password. We
highly recommend Bitwarden or 1Password —
they back your codes up, so a lost or broken phone does not lock you out. - Have your Medic52 password ready — you stay logged in during setup, but you will need the
password later if you ever regenerate backup codes.
How do I turn on two-factor authentication?
Set up two-factor authentication from your personal settings page:
- Log in to Medic52 on the web.
- In the sidebar, open Settings, then choose My Settings.
- Find the Two-Factor Authentication panel and click Enable.
- Open your authenticator app (or password manager) and scan the QR code Medic52 shows.
Can't scan? Click the manual key shown under the QR code and type or paste it into your app
instead. - Your app now shows a 6-digit code that changes every 30 seconds. Enter the current code in
the Authentication code field and click Confirm. - Medic52 shows your backup codes. Save them before you leave the page — see the next
section.
Two-factor authentication is now active on your account.
Where should I keep my backup codes?
Backup codes are one-time codes that let you log in if you lose access to your authenticator
app — for example, if your phone is lost, broken, or replaced. Each backup code works exactly
once.
- Best option: save the backup codes in your password manager, such as
Bitwarden or 1Password, in a secure note
attached to your Medic52 login. - Acceptable: print the codes and store the paper somewhere locked, away from your computer.
- Never: keep the codes as a screenshot in your camera roll, in an email to yourself, or on
a sticky note. Anyone who finds them can bypass your second factor.
You can view or replace your backup codes at any time from Settings → My Settings →
Two-Factor Authentication using Show backup codes or Regenerate backup codes (both
ask for your current password). Regenerating cancels all previous backup codes.
How do I log in once two-factor authentication is on?
After you enter your email and password (or use a magic login link), Medic52 asks for the
6-digit code from your authenticator app. Enter the code to finish logging in. The same check
applies in the Medic52 mobile app.
If you don't have your authenticator app with you, click Use a backup code instead and
enter one of your saved backup codes. Remember each backup code works only once.
Frequently asked
I lost my phone — how do I get back into Medic52?
Log in with your password, then click Use a backup code instead and enter one of your saved
backup codes. Once you are in, go to Settings → My Settings → Two-Factor Authentication and
set up your new phone. If you have no backup codes left, ask your manager to contact Medic52
support so we can verify your identity and reset two-factor authentication for you.
Can I turn two-factor authentication off?
You can disable two-factor authentication from Settings → My Settings → Two-Factor
Authentication by clicking Disable and confirming your password — unless your resort
requires it. If your resort enforces two-step verification, Medic52 will not let you disable
it, and that is deliberate: it protects the patient information your account can access. See
How do I require two-factor authentication for my team?
Does two-factor authentication work in the mobile app?
Yes. The Medic52 mobile app asks for the same 6-digit code when you log in. If your resort
requires two-factor authentication and you have not set it up yet, the app walks you through
the same QR-code setup during login.