Multi-factor authentication

Last Updated: September 7, 2026

subQdocs Multi-Factor Authentication

Last Updated: September 7, 2026

Supported multi-factor authentication use cases for the subQdocs Health IT Module, per ONC certification criterion §170.315(d)(13).

This page is the public description of those use cases. It is the hyperlink submitted with the §170.315(d)(13) attestation and intended for publication on the ONC Certified Health IT Product List (CHPL).

Summary

subQdocs supports authentication of a user’s identity through multiple elements, using industry-recognized standards:

  • Something the user knows: their password.
  • Something the user has: a phone that receives a one-time passcode over SMS, or a single-use backup code issued at enrollment.

MFA applies to users of the Health IT Module (clinicians and practice staff). It is not a patient-portal login factor.

Supported use cases

1. User sign-in

After the user submits a valid username and password, subQdocs challenges them for a second factor before a session is issued. The second factor is a six-digit one-time passcode sent by SMS to the phone number enrolled on the account.

2. Enrollment

A user enrolls MFA by providing a mobile phone number, verifying possession of that number with an SMS one-time passcode, and confirming their password. At enrollment, subQdocs issues single-use backup codes. The user is instructed to store those codes outside the application.

When an organization requires MFA, a user who is not yet enrolled must complete enrollment before using the Health IT Module.

3. Backup-code sign-in

If the enrolled phone is unavailable, the user may complete the MFA challenge with one of their single-use backup codes instead of an SMS passcode. Each backup code can be used once.

4. Trusted device

After a successful MFA challenge, the user may choose to remember that device for 30 days. On a remembered device, subQdocs does not prompt for the second factor again until the trust period ends or an administrator resets MFA for that user.

5. Organization-required MFA

An organization administrator may require MFA for every user in that organization. While the requirement is on, users must enroll and complete the SMS (or backup-code) challenge in order to use the application.

6. Administrator reset

An administrator may reset a user’s MFA enrollment (for example if the user lost the phone and the backup codes). Reset clears the enrolled second factor and trusted devices for that user. The user must enroll again before the next sign-in when MFA is required.

Standards

  • Second-factor delivery: SMS one-time passcode (six digits).
  • Recovery: single-use backup codes issued at enrollment.
  • Password remains the first authentication element and is stored hashed at rest.

subQdocs does not currently offer authenticator-app (TOTP) MFA. If additional MFA methods are added, this page will be updated and the change reported through the Drummond quarterly attestation process.

×