A compromised password shouldn't be enough to access the information of an entire clinic.
Therefore, organization administrators in Itaca can now enable the two-step email verification. When enabled, every member who logs in with a password must also enter a code sent to their email.
The setting applies to the entire organization. There is no need to ask each member to enable it separately or to install an additional authentication app.
A single policy for the entire team
In a clinic or private practice, access security should not depend on each person remembering to configure an individual option. The administrator defines the policy once, and it is applied to those who access with email and password.
This makes it possible to establish a consistent access method for doctors, assistants, administrative staff, and other members of the organization. It also prevents a new invitation from ending up creating an account without first verifying that the person can access the specified email.
How two-step verification works
- The user enters their email and password as usual.
- Itaca sends a 6-digit numeric code to that person's email.
- The user enters the code in Itaca. Only then is the login completed.
The code expires after 10 minutes. If the message does not arrive, a new one can be requested after 60 seconds; doing so renders the previous code invalid. After 5 incorrect attempts, it is necessary to start over.
More protection without adding another app
Authenticators and physical keys offer valuable options, but they can also add friction for teams not accustomed to using them. Email is already part of the daily work of most clinics.
Email verification adds a second check to password-based access using a known channel. Thus, the organization can strengthen login without asking the team to configure a device or learn a new tool.
This measure complements, but does not replace, good access practices: each person must use their own account, choose a unique password, and also protect their email.
What changes for the members of the organization
- Password accesses require the code. The policy is applied according to the user's active organization.
- Existing sessions are not interrupted. The code will be requested at the next full password login.
- New guests verify their email. If they join an organization that requires this protection, they do not receive a session until they complete the code.
- It works on the web and in mobile apps. The same flow is available on iPhone, iPad, and Android.
- Sign in with Google or Apple does not change. Email verification applies to password login.
How to activate it in Itaca
The option is available only to organization administrators.
- Abra Preferences.
- Go to the tab Account.
- Active Email two-step verification.
The policy takes effect for the organization. If an administrator decides to disable it later, Itaca requests a code by email before confirming the change.
When is it a good idea to enable it
We recommend enabling it when several people work within the same organization, especially if the team accesses from different locations or devices. It is also useful for a private consultation that incorporates a secretary or assistant and wants to maintain a common access rule from day one.
Two-step verification is a specific piece within a broader policy. To evaluate other aspects, please consult our guide on security in medical platforms and the checklist for choosing clinic software.
Enable a common access rule for your organization
One setup, a clear workflow, and the same expectation for the entire team. Enable two-step verification from the administrator account and inform your members that they will receive a code the next time they log in with a password.





Leave a Reply