Two-step verification

Turn on a 6-digit authenticator code at sign-in, keep a backup so you don't get locked out, and reset it for a team member who has lost their device.

Practice management5 min readUpdated

Two-step verification asks for a 6-digit code from an authenticator app on top of your usual sign-in. A stolen or reused password stops being enough on its own, which is the single most useful thing you can do for an account that reaches patient records.

It's per person and optional. You turn it on for yourself; there is no organization-wide switch that forces it on everyone. Owners and admins can't turn it on for someone else — but they can clear it if that person gets locked out.

Turning it on

Go to Settings → Security. The Two-step verification section shows Not enabled.

  1. Click Set up. You'll be asked to confirm it's you first — your password, or Confirm with Google / Confirm with Apple if that's how you sign in. This step is deliberate: it stops anyone who wanders up to an unlocked laptop from attaching their own authenticator to your account.
  2. Scan the QR code with your authenticator app. Google Authenticator, 1Password, Bitwarden, Authy and the built-in iPhone and Mac password managers all work — Ona doesn't care which. If you can't scan, open Can't scan the code? and type the setup key in by hand.
  3. Enter the 6-digit code the app is showing and give the authenticator a name, e.g. "iPhone". The name is only so you recognise it later on this page.

That's it — the section flips to Enabled, and the next time you sign in you'll be asked for a code.

If the section says "Unavailable"

Your email address hasn't been confirmed yet, and two-step verification can't be switched on until it is. Click Send verification email, open the link in your inbox, and come back. This is common on accounts that were created for you rather than by you.

Keep a backup before you close that screen

Scan the same QR code into a second app while it's on screen — your phone and your password manager, say, or two phones. Both will then generate the same codes, so losing one device is an inconvenience rather than a lockout.

This is worth doing at set-up because it's the only convenient moment. Ona holds one authenticator per account, so you can't come back later and add a second one — and once you leave the set-up screen, the code is gone. If you skipped it, remove the authenticator and set it up again, scanning into both apps this time.

Ona doesn't issue printed backup codes. The fallback is the reset described below.

Signing in once it's on

Sign in as usual with your email and password, or with Google or Apple. Then you'll be asked for the 6-digit code before you land in Ona. Codes refresh every 30 seconds; if one is rejected, wait for the next one and try again rather than retyping the same digits.

It applies everywhere you sign in — the main sign-in page, the patient portal, the booking pop-up, and the link in a team invitation.

A code that has just been used can't be used twice, and the prompt doesn't survive a page refresh. If you reload mid-sign-in, start again from your password.

Turning it off

Settings → Security → Remove, then confirm. You'll be asked to confirm it's you first, the same as when you set it up.

For security, removing the authenticator sometimes signs you out on the spot. That's expected — sign back in with your password.

If someone on your team is locked out

An owner or admin clears it for them:

  1. Settings → Team Members, then click the person to open their panel.
  2. Under Personal info, scroll to Two-step verification. It shows their authenticator's name and when it was added, or "Not enabled".
  3. Click Reset and confirm.

Four things happen. Their old authenticator stops working. They're signed out on their other devices shortly afterwards — within the hour, not the same second. They can sign in with their password alone and set up a new authenticator. And they get an email telling them it happened and who did it, so an unexpected reset doesn't pass unnoticed.

Nothing else about the account changes: their roles, licence and patient assignments are untouched.

Why you can't reset your own

The Reset button is replaced by a link to your own settings when you open your own panel. Letting an admin session strip its own second factor would undo the point of having one — anyone who got hold of that session could clear the protection and carry on.

If you're an owner or admin and it's your phone that's gone, ask another owner or admin to reset it for you. It's a good reason to make sure at least two people in the practice hold the Admin role. Team members who have joined but never signed in show as "Hasn't joined yet" and have nothing to reset.

Patients

Patients can do exactly the same from Settings → Security in the patient portal, on the same terms. If a patient loses their authenticator, they contact the clinic and an owner or admin clears it.

Not the same as prescription signing

If you prescribe controlled substances, you already meet a two-factor prompt when signing — that's DoseSpot's EPCS, required by the DEA, and it's separate. Turning two-step verification on or off here changes nothing about prescription signing, and EPCS doesn't protect your Ona sign-in. Most prescribers want both.

Related guides

Can’t find what you’re looking for?

Book a demo and we’ll walk you through it live — or email contact@ona.health and a human will help.