Skip to main content
The Security Center covers account security, privacy and compliance. Every authenticated user can open it and manage their own account security.

Account security

Organization and privacy

Turning on two-factor authentication

Because OfficeRidge holds protected health information, two-factor authentication is the single most useful thing you can do to protect member data.
1

Open Two-Factor Authentication

From the Security Center.
2

Follow the setup prompts

You will register an authenticator app that generates verification codes.
3

Save your backup codes somewhere safe

These are how you get in if you lose your device.
4

Set up account recovery

Recovery email, phone, and trusted contact give you a route back in.
Store your backup codes outside OfficeRidge and outside the device running your authenticator app. Backup codes kept only on the phone you are authenticating with are useless when that phone is lost.

Trusted devices

A trusted device can skip the two-factor prompt on subsequent sign-ins.
Only trust devices you personally control. Never trust a shared or public computer — anyone using it afterwards can reach your account, and therefore member records, without a verification code.
Review trusted devices periodically and remove any you no longer use.

Reviewing security alerts and login history

1

Check security alerts

Flagged sign-ins and new devices appear here.
2

Review login history

Look for sign-ins you do not recognise — unfamiliar times, locations, or devices.
3

Check active sessions

End any session you do not recognise.
4

Change your password if anything looks wrong

Then remove unrecognised trusted devices.
5

Report it

Tell your compliance officer. Unauthorised access to an account with member data may be a reportable security incident. See HIPAA compliance.
An unrecognised sign-in on an account with member record access is potentially a HIPAA security incident, not just a personal account problem. Report it rather than simply changing your password and moving on.

Data export and account deletion

Data export lets you download a copy of your data. Account deletion permanently removes your account.
Account deletion is permanent. It is separate from organization deletion — deleting your own account does not delete your agency’s records, and it will remove your access entirely. If you are leaving the agency, an admin should remove you from the organization team instead.

Troubleshooting

HIPAA compliance

Security incidents and the PHI access trail.

Account

Your display name and preferences.