What is multi-factor authentication?
Multi-factor authentication (MFA) adds an extra layer of security to your account. Instead of just entering a password, you'll also need to provide a second form of verification when logging in to the Dashboard and Sidebar.
MFA is required for all HotDoc user accounts, to strengthen account security and protect sensitive data.
Once MFA is set up, you'll be required to enter a secure, one-time code each time you sign in. This code can be delivered in one of two ways:
- Using an Authenticator App
- Via Email
|
Using an authenticator app is the most secure option and is recommended. However, receiving codes via email may be suitable if your email account is already protected with strong security (such as its own MFA). If you're unsure which option is best for your setup, check with your IT team or security provider. |
If using the authenticator app method:
You'll be required to download an authenticator app. Our recommended applications are Authy, Microsoft Authenticator or 1Password. You only need to select one of these applications. To find more information about each app, please click the links below:
If using the email method:
You don't need to download any additional apps. Once MFA is enabled, a one-time code will be sent to your email each time you log in.
How can I enable multi-factor authentication for my account?
MFA is required for all HotDoc user accounts. When a new HotDoc user account is created, you'll be required to set up MFA the first time you log in to the Dashboard or Sidebar with that account.
| If you share a HotDoc user login with other colleagues and would like to set up MFA on multiple devices, please follow the steps under How can I enable multi-factor authentication on multiple devices? |
-
To start setting up MFA, click Get Started
-
Choose whether you would like to receive your one-time codes via Authenticator app or Email. Enter your current Dashboard password, and select Continue.
Authenticator app option Email option -
If you selected Email, skip to step 7. If you selected Authenticator app, continue below.
-
Choose one authenticator app from the options provided – Authy, Microsoft Authenticator, or 1Password. You only need one of these. Download and open your chosen app on your device.
-
In your authenticator app, use the option to add a new account and scan the QR code shown on screen. If you can't scan it, select Copy next to the setup code and enter it manually instead.
-
Enter the 6-digit code your authenticator app generates into the One time code box, then select Next. Skip to step 8.
-
If you selected Email, we'll send a one-time code to your email address. It will be sent to the email address for the user account you're currently signed into. Enter this code when prompted to verify your email.
-
Once your method is verified, you'll be shown a set of recovery codes. Select Download or Copy and store these somewhere safe and separate from your authentication method.
Recovery codes let you log in if you lose access to your authentication method. Each code can only be used once. -
Select Finish setup.
-
Confirm you've saved your codes by selecting Yes, I've saved them.
-
You'll then see confirmation that MFA is enabled on your account. Select Go to Dashboard or Continue.
If you set up authenticator app If you set up email verification
How can I enable multi-factor authentication on multiple devices?
|
We strongly recommend creating a new user for each individual. There is no additional cost for setting up extra logins. To do this, you can follow the steps in: How to create, edit or delete a User Account
|
If you share a HotDoc login with multiple colleagues, most clinics find it simplest to use the email method – anyone with access to the shared inbox can retrieve the one-time code, so you can simply follow the steps outlined above: How can I enable multi-factor authentication for my account?
If you'd rather use an authenticator app that everyone sharing the login can access, you can set this up on multiple devices by following the steps below.
|
Please note: It's required that all individuals who will be setting up MFA on their own device are present for the setup. Once the setup is complete, you cannot re-scan the QR code to add another individual/device to the same Dashboard login. |
-
You will be prompted to set up MFA the first time you log into your Dashboard or Sidebar with a new user account. Click Get Started.
-
Select Authenticator app as your authentication method, enter your current password, and click Continue.
Authenticator app option -
Choose one authenticator app from the options provided – Authy, Microsoft Authenticator, or 1Password. You only need one of these.
Install the authenticator app of your choice on all relevant devices (ensure everyone who uses this login will have access to the authenticator application on a device of their choosing i.e. mobile phone or computer).
-
On each device, use the option to add a new account and scan a new code to scan the QR code provided on the Dashboard screen. Each individual will use their own device to scan the same QR code from the Dashboard.
If you can't scan it, select Copy next to the setup code and enter it manually instead.
-
Enter the 6-digit code your authenticator app generates into the One time code box, then select Next.
-
Once your method is verified, you'll be shown a set of recovery codes. Select Download or Copy and store these somewhere safe and separate from your authentication method.
For security reasons, please ensure that you do not share the QR code or the setup code with anyone else. ⓘ Important information
How can I reset multi-factor authentication for my account?
If you'd like to change your MFA method – for example, switching from email to an authenticator app – you can reset MFA for your account and set it up again using your preferred method.
MFA can't be turned off completely, as it's a required security feature for all HotDoc accounts.
|
If you can't access your current authentication method (for example, you've lost access to your authenticator app or email account) and need to reset MFA, you'll need to either:
|
-
Log in to your HotDoc Dashboard.
-
Select the down arrow at the top right of your page, next to your email address.
-
Click My Account.
-
Enter your current Dashboard password
If your password is entered incorrectly, you will see an error. Please reenter the correct password, or reset your password if necessary. ⓘ Please note -
Select Reset multi-factor auth
-
Confirm Set up MFA
-
Click Get started and follow the prompts to set up your chosen authentication method. These are the same steps shown in How can I enable multi-factor authentication for my account?
| If you were previously using an authenticator app, please delete the old entry from your authenticator app, as it will no longer work. |
FAQs
My clinic shares one login between multiple staff members – what should we do?
+
We strongly recommend each staff member has their own individual HotDoc login – this gives you proper audit trails and means MFA protects each person individually. See How to create, edit or delete a User Account.
If creating individual logins is not possible, using MFA is still required.
Most clinics in this situation use the email MFA method, using an email address that all staff can access, so everyone can retrieve the one-time verification code.
Alternatively, you can use an authenticator app that all staff can access – see How can I enable multi-factor authentication on multiple devices?
What should I do if I'm having trouble entering my code or I didn't receive it?
+
See I'm having trouble with my multi-factor authentication code for troubleshooting steps, including what to do if you didn't receive a code at all.
Why is it recommended to use the authenticator app method instead of the email method?
+
The authenticator app method is recommended because it provides a stronger and more reliable layer of security than email. This is particularly important when a shared email address is used, to ensure that access points are limited.
Using an authenticator app keeps the authentication step tied to the person signing in, providing greater control over who can access the HotDoc account.
I no longer have access to my email address or authenticator app – what should I do?
+
If you're unable to access your email address or authenticator app to get your authentication code, you should use one of your saved recovery codes to regain access to your account. This will allow you to reset MFA.
If you have no recovery codes available, you can follow the account recovery steps.