Last modified: November 6, 2024
Securing your patient account with 2-step verification
Overview
Keep sensitive information between you and your practitioner by adding 2-step verification in a few quick steps! Get peace of mind knowing that your health and financial data is protected by an added layer of security on Fullscript.
When enabled, anyone attempting to access your account will need to enter your password and an authentication code to log in successfully. This added security measure is optional.
You can choose between one of three security methods:
- Use your email linked to your Fullscript account: We’ll send a login code to the email used to log into Fullscript.
- Authentication app (recommended): Download an authentication app, such as Google Authenticator, Microsoft Authenticator, LastPass Authenticator, Twilio Authy Authenticator, etc. to receive one-time login codes.
- SMS: We’ll send a text with a verification code to the phone number associated with the account.
Setting up 2-step verification from your Account settings
To set up 2-step verification:
- Click your avatar or initials from the navigation bar.
- Click My account.
- Under Password, find 2-step verification and click Set up.
- Then, choose the security method you want to use and follow the on-screen instructions: Email or Authenticator app.
Enabling 2-step verification: Codes delivered to email inbox
When enabling 2-step verification, you can choose between having a login code sent to your email inbox or a third-party authentication app. With the email option, we’ll send a unique 6-digit security code to the email address you use to log in anytime someone tries logging into your Fullscript account.
To enable 2-step verification with the email option:
- After clicking Set up in your Account settings, select Use your email linked to your Fullscript account.
- Click Next.
- Check your email inbox for your one-time code.
- Enter your one-time code and click Confirm.
- Copy your backup code or take a screenshot of it and store it in a private folder on your device.
- Then, click Done.
Enabling 2-step verification: Authenticator app option
You can choose to enable 2-step verification and log in with one-time codes generated by an authenticator app, such as Google Authenticator, Microsoft Authenticator, LastPass Authenticator, or Twilio Authy Authenticator.
To enable 2-step verification using an authenticator app:
- After clicking Set up in your Account settings, select Use an authenticator app.
- Click Next.
- Download or open the authenticator app on your mobile device.
- Back in Fullscript, click Next.
- Using your mobile device, scan the QR code or manually enter the code in your authenticator app.
- Click Confirm.
- Copy your backup code or take a screenshot of it and store it in a private folder on your device.
- Then, click Done.
Enabling 2-step verification: SMS option
You can choose to enable 2-step verification and log in with one-time codes sent to your phone via SMS.
To enable 2-step verification using SMS:
- After clicking Set up in your Account settings, select Use text message.
- Click Next.
- Enter your mobile number to receive a one-time code.
- Select Next.
- Enter the code sent to your mobile device and select Next.
- Copy your backup code or take a screenshot of it and store it in a private folder on your device.
Logging in with a one-time code
When 2-step verification is enabled, we’ll ask you for a one-time code in addition to your password each time you sign in to confirm your identity.
To log in with your one-time code:
- Log into your Fullscript account with your email address and password.
- Enter the one-time code that was sent to your email or generated from your authenticator app.
- Click Next.
Disabling 2-step verification
Disable 2-step verification at any time by going to Password under your My account, click Manage next to 2-step verification and click Disable.
2-step verification on iOS and Android
Fullscript’s 2-step verification process can’t be enabled or disabled in the mobile app experience. However, using FaceID is another valid verification method that bypasses 2-step verification when used during sign-in.