Two-Factor Authentication
You can require organization members to enter a one-time passcode in addition to their password when logging into the EMR.
Prerequisites
Part 1: Add a phone number to each user's account (EMR)
Two-factor authentication codes are delivered by SMS, so every user you enable must already have a phone number on their Avon account.
Follow the instructions here to add a phone number when you set up an organization member.
Steps
Step 1: Enable 2FA for users (EMR)
To turn on two-factor authentication:
- Go to the EMR (e.g. emr.avonhealth.com)
- Click on the hamburger menu on the top left corner > Settings > Organization > Admin Panel (e.g. https://emr.avonhealth.com/settings/organization/admin-panel)
- Select the users you want to enable, either:
- Check the box next to each user one by one OR
- Check the box in the table header to select everyone in the organization
- Click "Enable 2FA"
Notes:
- Users added to your organization later do not inherit 2FA automatically. It's worth building this step into your onboarding process for new staff so that every new user gets enabled.
- Selecting everyone in the table header enables 2FA for every user in the organization at that moment, but it is a bulk action rather than a persistent organization-wide policy. It does not carry forward to users you add afterwards.
Step 2: Review who has 2FA enabled (EMR)
The admin panel shows 2FA status per user, so you can see who is enabled from the same page:
- Go to the EMR (e.g. emr.avonhealth.com)
- Click on the hamburger menu on the top left corner > Settings > Organization > Admin Panel
- Review the 2FA status column for each user in the table
Supported methods
- SMS one-time passcode (OTP) for two-factor authentication
- Google SSO for login