...

Ekim IT Solutions

Blog / How to Enable MFA for Your Dental Practice
All Dental

How to Enable MFA for Your Dental Practice

Multi-factor authentication setup guide for Microsoft 365, Dentrix Ascend, and Open Dental in a dental practice

A stolen password should not be enough to reach patient data. MFA adds the second proof an attacker still has to defeat after the credential is compromised.

For a dental practice, that protection needs to cover email, the practice-management platform, remote access, and every other system that can expose PHI or administrative control.

Coverage Gap

Protecting email with MFA does not solve the problem if the PMS or remote-access gateway is still password-only.

The article argues for a coordinated rollout across every system that can reach patient data, rather than treating MFA as a platform-by-platform afterthought.

MFA works best as a coordinated control across email, the PMS, remote access, and the other systems that can reach patient information.
Schedule a Discovery Call

Microsoft 365 MFA Rollout Path

The setup should move from administrator access to staff enrollment and then to verification.

Admin CenterSign in with a Global Administrator account.
Select Staff AccountsOpen active users and enable MFA for the practice accounts.
Register Second FactorHave staff enroll their authenticator method at next sign-in.
Verify EnrollmentConfirm each user completed MFA before considering the rollout finished.

Choose the Stronger Second Factor Where Possible

The article prefers authenticator-app MFA over SMS for the practice accounts it describes.

Preferred

Authenticator App

App-based codes operate independently of SMS delivery and are the article’s recommended default for Microsoft 365 and Curve Dental where supported.

Use With Caution

SMS Codes

The article notes that SMS-based codes can be exposed to SIM-swapping risk, which is why app-based MFA is preferred for dental-practice staff accounts.

MFA Looks Different Across Dental PMS Platforms

The control should be enabled where the platform supports it directly, or enforced at the surrounding Windows and remote-access layer where it does not.

Cloud PMS

Dentrix Ascend

The article describes enabling MFA for all users through the practice administration security settings and verifying enrollment for every account.

Cloud PMS

Curve Dental

The article describes MFA through the practice security settings, with authenticator-app MFA preferred over email-based verification.

Server-Based PMS

Open Dental

The article says MFA is enforced around the PMS through Windows sign-in, Active Directory, VPN, or Remote Desktop gateway controls rather than a native PMS login factor.

For Open Dental, Put MFA Around the Access Path

The article treats Windows and remote access as the enforcement boundary for server-based Open Dental environments.

User Sign-InWindows Hello or another MFA-capable Windows authentication method.
MFA ENFORCEMENT
Remote AccessVPN or Remote Desktop gateway protected with MFA before remote connectivity is granted.
Open DentalThe PMS sits behind those identity and remote-access controls.
HIGH-RISK
GAP
Security Risk Assessment

MFA belongs on the list of controls reviewed wherever systems can access ePHI.

The article frames missing MFA on email and PMS access as an unmitigated credential-risk gap that should be documented and addressed as part of the practice’s security program.

See What Happens After a Password Is Stolen

Choose the system being targeted, then compare the same stolen credential against password-only access and MFA-protected access.

1. Choose the target system
2. Choose the sign-in protection
Credential StolenPhishing or another credential attack exposes the user’s password.
Attacker Tries LoginThe stolen password is entered against the real account.
Access DecisionThe outcome now depends on whether a second factor is required.
Password Accepted The stolen credential is enough to continue into the account because there is no second authentication step to stop it.
Attack Stopped at the Second Factor The password alone is not enough. The attacker still has to satisfy the MFA challenge before the account can be accessed.
PMS impact: A compromised PMS account can expose scheduling, patient records, billing information, and other high-value practice data.
Remote-access impact: A compromised VPN or Remote Desktop path can give an attacker a route into the practice environment itself.

Dental Practice MFA Rollout Checklist

The rollout is complete only when the systems that can reach patient data are protected and staff enrollment has been verified.

1
Enable MFA on Microsoft 365 or the practice email platform
2
Enable MFA on cloud PMS platforms that support it directly
3
Protect Windows, VPN, and Remote Desktop access where the PMS itself does not provide MFA
4
Prefer authenticator-app MFA where practical
5
Verify enrollment for every staff account before closing the rollout
6
Document MFA coverage in the practice’s security risk assessment

Frequently Asked Questions

The 2024 proposed HIPAA Security Rule updates move MFA toward explicit requirement status for systems accessing ePHI. Current HIPAA Security Rule guidance identifies it as an addressable specification with very limited basis for not implementing it. HHS has explicitly called out MFA as a fundamental control in ransomware guidance. Every dental practice SRA should treat absent MFA as a high-risk finding requiring immediate remediation.
Authenticator apps including Microsoft Authenticator and Google Authenticator provide the most phishing-resistant MFA for dental practice staff. SMS text code MFA is significantly better than no MFA but is vulnerable to SIM swapping. Hardware security keys provide the strongest protection but require physical device management. Ekim IT Solutions recommends Microsoft Authenticator as the standard second factor for Tampa Bay dental practices.
On a new login from an unrecognized device, yes by approximately 15 seconds. For recognized devices, Conditional Access policies can be configured to not require MFA on every login, only on new device registrations or suspicious sign-in patterns. Ekim IT Solutions configures Conditional Access for Tampa Bay practices that want to minimize friction while maintaining MFA protection.
Yes. Ekim IT Solutions configures and enforces MFA on Microsoft 365, Dentrix Ascend, Curve Dental, remote access systems, and other PHI-accessing platforms for Tampa Bay dental practices, including staff enrollment and verification that every account is covered.
Still relying on passwords alone to protect your email and cloud PMS?

Ekim IT Solutions serves Tampa Bay from our office at 600 N Westshore Blvd, Suite 701. We enable MFA across every system your staff actually uses, so a phished password alone can never get an attacker into your accounts.

MFA set up across every system your staff uses.
Get an MFA setup review →