Overview
After your account is approved, your first login involves setting a secure password and configuring two-factor authentication (2FA). The platform enforces strong security defaults to protect sensitive patient data and clinic operations.Setting your password
Check your email for the password setup invitation from the platform. Click the link to open
the password setup page.
The invitation link expires after 7 days. If the link has expired, ask your clinic
Admin to resend the invitation from the staff management panel.
Configuring two-factor authentication
After your first successful login, the platform prompts you to set up two-factor authentication (2FA). This adds a second layer of security beyond your password.Available 2FA methods
Email OTP
A 6-digit code sent to your registered email. This is the default method enabled
for all accounts.
Authenticator App
Time-based one-time passwords (TOTP) via apps like Google Authenticator or Authy.
Passkeys
Biometric authentication using FaceID or TouchID via the WebAuthn standard.
Email OTP (default)
Email OTP is automatically enabled when you set up 2FA. Each time you log in:- Enter your email and password
- A 6-digit code is sent to your registered email
- Enter the code on the verification screen
Email OTP codes are valid for 10 minutes. If the code expires, request a new one
from the login screen.
TOTP authenticator app
For faster and offline-capable authentication, configure a TOTP authenticator app:Open your authenticator app (Google Authenticator, Authy, or any TOTP-compatible app)
and scan the QR code displayed on screen.
Passkeys (FaceID / TouchID)
Passkeys provide the most seamless login experience using your device’s biometric capabilities:Click Add Passkey and follow your browser’s prompts to register your device using
FaceID, TouchID, or another WebAuthn-compatible method.
You can register only one passkey per account. If you need to switch devices,
remove the existing passkey from Settings > Security before registering a new one.
Session security policies
The platform enforces several session-level protections to keep your account safe:Login lockout
If you enter the wrong password 5 times in a row, your account enters a 10-minute cooldown period. During this time, no login attempts are accepted — even with the correct credentials.The lockout timer resets automatically after 10 minutes. If you are locked out
frequently, consider resetting your password.
Single-session enforcement
The platform allows only one active session per user at a time. If you log in on a new device or browser, your previous session is terminated automatically. This means:- You cannot be logged in on your desktop and phone simultaneously
- Logging in on a new device immediately logs you out of the old one
- There is no warning before the old session is ended
Session timeout
Your session automatically expires after 30 minutes of inactivity. When your session times out:- You are redirected to the login page
- Any unsaved work may be lost
- You must re-authenticate with your password and 2FA
Frequently asked questions
Can I disable 2FA?
Can I disable 2FA?
No. Two-factor authentication is mandatory for all your accounts to comply with
data security requirements for healthcare platforms.
What if I lose my phone with the authenticator app?
What if I lose my phone with the authenticator app?
Contact your clinic Admin or our support team to regain access. They can reset
your 2FA so you can reconfigure it from a new device.
Can I use multiple 2FA methods at the same time?
Can I use multiple 2FA methods at the same time?
Yes. You can have email OTP, an authenticator app, and passkeys all configured
simultaneously. During login, you choose which method to use.
What happens if my invitation link expires?
What happens if my invitation link expires?
Ask your clinic Admin to resend the invitation from the staff management panel. The
new link resets the 7-day expiry window.
Related articles
- Signup & Approval — How to create your account and get approved
- Roles & Permissions — Understand what you can access based on your assigned role
- Inviting Staff — How Admins send invitations and manage the onboarding flow

