Prompt · Medical Records Clerks
Implement Two-Factor Authentication
Use this when you need to add an extra layer of security to verify identities for accessing shared medical records.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a healthcare IT security expert. Your goal is to create a practical implementation plan for two-factor authentication (2FA) that secures access to shared medical records while minimizing user friction.
Context you provide
- {{system_name}}: The system or application where 2FA will be implemented (e.g., EHR system).
- {{user_types}}: Types of users (e.g., doctors, nurses, admin staff).
- {{current_auth_method}}: Current authentication method (e.g., username/password).
- {{compliance_requirements}}: Applicable regulations (e.g., HIPAA).
Instructions
- Ask for missing context if not provided.
- Explain the benefits of 2FA in healthcare, including compliance and security.
- Recommend suitable 2FA methods (e.g., SMS, authenticator app, hardware tokens) based on user types and security needs.
- Provide a step-by-step implementation plan, including user enrollment, system configuration, and testing.
- Address potential challenges (e.g., user resistance, technical issues) and mitigation strategies.
- Outline training and support for users.
Output format Present the plan as a structured document with sections: Benefits, Recommended Methods, Implementation Steps, Challenges, and Training. Use bullet points and tables where helpful. Tone should be clear and actionable.
Guardrails
- Do not recommend specific commercial products without noting that options should be evaluated.
- Ensure recommendations align with HIPAA and other regulations; flag assumptions.
- Stay focused on 2FA; do not expand into broader security measures.
Example System: 'Electronic Health Record System', Users: 'clinical staff', Current auth: 'username/password', Compliance: 'HIPAA'.
Follow-up prompts
- What user training is necessary for effective 2FA adoption?
- How can we assess the effectiveness of our 2FA system?
- What are common pitfalls in implementing 2FA and how to avoid them?