1. Home
  2. Knowledge Base
  3. Security
  4. How do I require two-factor authentication (2FA) for my team?

How do I require two-factor authentication (2FA) for my team?

This article is for resort managers and administrators. It explains why enforcing two-factor
authentication (2FA, shown in Medic52 as two-step verification) matters for the patient
information your team handles, and shows how to turn enforcement on for your whole resort in
under a minute.

Why should my resort enforce two-factor authentication?

Your Medic52 accounts can reach patient and incident records — some of the most sensitive data
your organisation holds. A password alone is weak protection: passwords get reused, phished,
and leaked. Two-factor authentication means a stolen password is not enough to reach patient
data, because the attacker also needs the 6-digit code from the account holder's phone.

Enforcing it is also a compliance question, not just good practice:

  • United States — HIPAA. The HIPAA Security Rule requires covered entities and business
    associates to verify that the person seeking access to electronic protected health
    information is who they claim to be, and to manage identified risks to that information.
    Regulators have repeatedly cited missing multi-factor authentication in breach enforcement
    actions, and proposed updates to the Security Rule make multi-factor authentication an
    explicit requirement. If your team handles US patient information without enforced 2FA, you
    risk being unable to demonstrate HIPAA compliance — and you carry that risk on every account
    you leave unprotected.
  • Canada — PIPEDA and provincial health privacy laws. PIPEDA's safeguards principle
    requires security proportional to the sensitivity of the information, and provincial health
    information laws (such as Ontario's PHIPA) hold health information custodians to a high
    standard. Privacy regulators' guidance consistently names multi-factor authentication as an
    expected safeguard for sensitive personal information.
  • Australia — Privacy Act 1988. Australian Privacy Principle 11 requires reasonable steps
    to protect personal information, and health information is classed as sensitive information,
    which raises the bar for what "reasonable" means. The OAIC's security guidance and the
    Australian Cyber Security Centre's Essential Eight both list multi-factor authentication as a
    baseline control.

Important: This article is general information, not legal advice. Requirements differ by
country, state, and province — confirm your obligations with your privacy officer or legal
counsel. Whatever the local wording, enforcing two-factor authentication is the single
cheapest step you can take toward meeting it.

Before you begin

  • You need the Manager role (or administrator) — Resort Settings is hidden otherwise.
  • Tell your team first. Each person enrols themselves with an authenticator app on their own
    phone, so share
    How do I set up two-factor authentication?
    before you switch enforcement on.

How do I turn on enforcement for my resort?

Enforcement is a resort-wide setting:

  1. In the sidebar, open Settings, then choose Resort Settings.
  2. Scroll to the Security section (or click Security in the section list).
  3. Turn on Enforce two-step verification.
  4. Under Who must set it up, choose the scope:
    • All users — everyone at your resort (recommended where patient data is handled).
    • Managers — administrators and managers only.
    • Managers + dispatchers — adds dispatchers to the above.
  5. Click Save changes.

Administrators and managers are always covered by every scope — a narrower scope never exempts
your highest-privilege accounts.

What happens to my team after I enforce two-step verification?

  • Everyone in scope gets a personal 30-day grace period. During it they see a reminder
    banner but can keep working.
  • After their 30 days, anyone in scope who has not set up two-factor authentication is taken
    straight to the setup screen at login and cannot use Medic52 until they enrol.
  • Anyone who joins your resort later gets their own fresh 30 days from their join date —
    new staff are never locked out on day one.
  • Users covered by enforcement cannot disable two-factor authentication on their own
    account while enforcement is on.
  • The mobile app enforces the same policy: a user who must enrol is walked through the same
    QR-code setup inside the app at login.

Which scope should I choose?

Choose All users if your team records patient or incident information — that is what the
privacy frameworks above expect, because any account that can open a patient record is a way
in. Use the narrower Managers or Managers + dispatchers scopes only as a staged
rollout on the way to All users, or where general users genuinely cannot reach patient data.

Frequently asked

A team member lost their phone and is locked out — what do I do?

They can log in with one of the backup codes they saved during setup, then re-enrol their
new phone from Settings → My Settings → Two-Factor Authentication. If they have no backup
codes left, contact Medic52 support — we will verify their identity and reset two-factor
authentication for them. Encourage everyone to keep backup codes in a password manager such as
Bitwarden or 1Password so this rarely happens.

Does enforcement apply to the mobile app too?

Yes. The Medic52 mobile app asks for the same 6-digit code at login, and it walks
not-yet-enrolled users through setup when their grace period requires it. There is no way to
use the mobile app to bypass your resort's policy.

Can I see who has set it up already?

Two-factor status is enforced automatically per user against your policy, so nobody in scope
can slip through past their grace period. If you need an enrolment report for an audit,
contact Medic52 support.

Was this article helpful?

Related Articles