Settings → Security
Combine least-privilege roles with 2FA and session controls.
What to notice
Role permissions
Two-factor auth
Auto logout
Session access
Roles & Permissions
Covered in full under Roles & permissions. In short: seven roles, 62 permissions, edited by toggle, saved per role as you go.
Security
- Auto-logout — how long a session may sit idle before it ends. Shorter is better on machines in shared areas; a reception desk should not stay signed in over lunch.
- Two-factor authentication — turn it on before real patient data goes into the system, not after.
- Password policy — minimum length and complexity for staff accounts.
- Session activity — where accounts are currently signed in.
The per-patient counterpart to these settings is the Access Audit Log on each patient record, which lists who opened it. Between the two you can answer both "who can see this?" and "who did see this?"
Still stuck?
Your onboarding specialist is one message away, and support answers within one business day.
Contact support