Skip to main content
Account is your personal hub: sign-in, alerts, and personal data. The page subtitle is Your sign-in, alerts, and personal data. Organization privacy review lives in the Security Center.

Who can use it

Every authenticated user, for their own account.

Signed in as

The hub shows the name and email on your current session so you can confirm you are changing the right account.

Sign-in & security

These pages still live under /security/… in the product. Open them from Account — that is the hub that lists them.

Preferences & data

Account deletion is permanent. It does not delete your agency’s records. If you are leaving the agency, an admin should remove you from the organization team instead.

What is not here

You cannot change your own role. Roles are assigned by an Organization Admin on the organization team.

Turning on two-factor authentication

Because OfficeRidge holds protected health information, two-factor authentication is the single most useful thing you can do to protect member data.
1

Open Two-Factor Authentication

From Account.
2

Follow the setup prompts

You will register an authenticator app that generates verification codes.
3

Save your backup codes somewhere safe

These are how you get in if you lose your device.
4

Set up account recovery

Recovery email, phone, and trusted contact give you a route back in.
Store your backup codes outside OfficeRidge and outside the device running your authenticator app. Backup codes kept only on the phone you are authenticating with are useless when that phone is lost.

Trusted devices

A trusted device can skip the two-factor prompt on subsequent sign-ins.
Only trust devices you personally control. Never trust a shared or public computer — anyone using it afterwards can reach your account, and therefore member records, without a verification code.
Review trusted devices periodically and remove any you no longer use.

One device at a time

OfficeRidge allows one active device per account. Signing in somewhere new signs out the previous device.
If you sign in on a second device, your first device is signed out — you will see an explanation rather than a page that quietly stops working. This is deliberate: shared logins are how member data leaks, and one session per account makes sharing impractical.
Active Sessions shows the device currently signed in and lets you sign out all other devices.
If you keep getting signed out unexpectedly, someone else is probably using your account. Change your password and tell your compliance officer — shared credentials on an account with member access is a reportable concern.

Notification preferences

Choose which emails and in-app alerts you receive. Each notification type can be delivered by email, in-app, or both.
Security notices cannot be disabled. Everything else is yours to turn on or off.

Reviewing security alerts and login history

1

Check security alerts

Flagged sign-ins and new devices appear here.
2

Review login history

Look for sign-ins you do not recognise — unfamiliar times, locations, or devices.
3

Check your active session

Sign out all other devices if anything looks wrong.
4

Change your password if anything looks wrong

Then remove unrecognised trusted devices.
5

Report it

Tell your compliance officer. Unauthorised access to an account with member data may be a reportable security incident. See HIPAA compliance.

Troubleshooting

Security Center

Privacy, compliance, and organization access review.

Switch organization

Change your active organization.