Two-factor authentication (2FA)
Two-factor authentication (2FA) adds a second step to your sign-in: after entering your password, you also enter a six-digit code from an authenticator app on your phone. We strongly recommend every clinic user enable 2FA, especially anyone with clinic admin or provider role.
Why 2FA matters for medical practices
Your ApexMentum account has access to patient health information. If a password is leaked (reused, phished, or guessed), a second factor stops the attacker cold — they can't sign in without your physical device. For HIPAA-aware practices, 2FA is one of the cheapest and most effective controls you can deploy.
What you'll need
A TOTP authenticator app on your phone:
- Google Authenticator (iOS / Android)
- 1Password (also great because it can autofill the code on your computer)
- Authy
- Microsoft Authenticator
Any standard TOTP app works.
Enable 2FA
- Click your name in the top-right and open Account settings.
- Go to the Security tab.
- Click Enable 2FA.
- You'll see a QR code. Open your authenticator app and scan it. The app adds an "ApexMentum" entry with your email.
- Your app will now show a 6-digit code that rotates every 30 seconds. Type the current code into ApexMentum to confirm.
- We show you a list of recovery codes — 10 one-time-use codes you can use if you lose your phone. Save these somewhere safe (password manager, printed and locked away). You won't be able to see them again after this page.
2FA is now active. On your next sign-in, you'll be prompted for a code after entering your password.
"Remember this device" for 30 days
After a successful 2FA sign-in, you'll see a Trust this device for 30 days checkbox. Check it and you won't be prompted for a code again on that browser for the next month. The trust is cookie-based — clearing cookies revokes it. We recommend leaving this off on shared computers.
Lost your phone
If you've lost access to your authenticator app:
- Go to the sign-in page and click Use a recovery code after entering your email and password.
- Enter one of the recovery codes you saved when enabling 2FA. Each code works only once.
- Once signed in, regenerate your 2FA from Security → Reset 2FA.
If you've also lost your recovery codes, contact your clinic admin. They can disable 2FA on your account so you can re-enroll. If you are the clinic admin, email support@apexmentum.com with proof of identity.
Disable 2FA
From Security → Reset 2FA → Disable. We don't recommend this — keep 2FA on if you possibly can.