Multi-Factor Authentication (MFA) Use Case Documentation for TiaMD
Purpose
This document outlines the use case for Multi-Factor Authentication (MFA) in compliance with ONC certification requirements. It describes how MFA enhances security for TiaMD EHR users by requiring multiple authentication factors to verify identity before accessing protected health information (PHI).
Scope
· Applies to all users accessing the TiaMD Web EHR system.
· Ensures compliance with ONC’s security and access control requirements.
· Covers login authentication operation.
MFA Use Case Scenarios
1. Initial MFA Registration on Microsoft Authenticator
Actors:
-
- · Authorized User
- · TiaMD EHR System
- · Microsoft Authenticator App
Preconditions:
· The user has successfully logged into TiaMD for the first time.
· Microsoft Authenticator is installed on the user’s mobile device.
Workflow:
1. After the first successful login, TiaMD displays a QR code for MFA setup.
2. The user opens the Microsoft Authenticator app.
3. The user selects Add Account > Work or school account > Scan QR Code.
4. The user scans the QR code displayed on the TiaMD system.
5. The TiaMD account is added to Microsoft Authenticator.
6. The system generates an OTP, and the user is prompted to enter it for verification.
7. Upon successful verification, MFA is registered, and the user is redirected to the TiaMD dashboard.
Postconditions:
· The user’s account is successfully linked to Microsoft Authenticator.
· Subsequent logins will require an OTP from the app.
2. User Login with MFA
Actors:
· Authorized User (e.g., provider, administrator, other clinical staff)
· TiaMD EHR System
· Microsoft Authenticator App
Preconditions:
· The user has valid credentials (username/password) registered in the system.
· MFA is enabled for the user account.
· The user has registered their TiaMD account on the Microsoft Authenticator app.
Workflow:
1. The user enters their username and password on the TiaMD login screen.
2. TiaMD verifies the credentials.
3. If valid, the system prompts the user for an additional authentication factor.
4. The user opens the Microsoft Authenticator app.
5. The system generates a one-time passcode (OTP) and sends it to the Microsoft Authenticator app.
6. The user enters the OTP from the app into TiaMD.
7. Upon successful verification, the user gains access to the TiaMD EHR system.
8. If MFA verification fails, access is denied.
Postconditions:
· The user is granted access only after successful authentication.
· 5 consecutive failed authentication attempt locks the account and needs intervention from administrator to unlock the account.
Compliance Considerations
· ONC Requirement: MFA must be implemented for users accessing PHI remotely and for high-risk transactions.
· HIPAA Alignment: MFA supports HIPAA security requirements for authentication and access control.
Troubleshooting
| Issue | Possible Solution |
| User does not receive OTP | Verify that Microsoft Authenticator is properly set up and has sync enabled. |
| MFA authentication fails | Ensure the correct OTP is entered or reset MFA settings from TiaMD. |
| User is locked out after multiple failures. | Contact administrator to unlock and reset account. |