Skip to main content

PatientNow Essentials / EnvisionNow: Two-Factor Authentication (2FA)

Overview

Two-Factor Authentication (2FA) in PatientNow Essentials adds an extra layer of security by requiring users to verify their identity with a one-time code sent to their email during login. Once enabled by an administrator, this applies to all users. During login, users confirm or enter an email address, receive a verification code, and enter that code to access the system. Most issues are related to incorrect email addresses or expired verification codes.


Table of Contents


Who This Applies To

  • Managers / Supervisors – Ensure staff follow security policies

  • Staff / Users – Complete 2FA during login


System Requirements

  • Each user must have a valid email address

  • Users must have access to their email inbox during login


Prerequisites

  • Employee profiles must be created and maintained.

Two-Factor Authentication Requirement

Two-Factor Authentication (2FA) is required for all users in PatientNow Essentials and is enabled by default. Administrators do not need to configure or enable this feature.

All users will be prompted to complete 2FA during login.


2FA Login Workflow

Step 1: Log In

  • Enter username and password

  • Click Log In

Note: 2FA begins only after valid credentials are entered.


Step 2: Confirm Email Address

  • Review the email shown (pulled from the Employee Profile)

  • Click Confirm and Continue


Step 2B: Email Required (If Missing)

  • If no email exists, the user is prompted to enter one

  • Click Save and Continue

Important: This email is saved and used for all future verification attempts.


Step 3: Confirm Email Popup

  • User is asked to confirm:
    “The verification code will be sent to: [email]”

  • Click OK to proceed

Important: This is the final confirmation before the code is sent.


Step 4: Receive Verification Code

Note: Codes are sent via email only. SMS/text is not supported.


Step 5: Enter Verification Code

  • Enter the code within 20 minutes

  • Click Continue

Note: Only the most recent code will work.

Remember This Device

  • Users can select “Remember this device”

  • If selected:

    • 2FA is skipped for 30 days

    • Applies only to that specific device/browser

  • If not selected:

    • 2FA will be required on the next login


Resending Codes

  • Users can request a new code if needed

  • A new code:

    • Is sent immediately

    • Invalidates any previously issued code


Where the Verification Email Comes From

The verification email is pulled from:

Employee Profile → Email field

Navigation path:

  • Employee → Employee List → Edit Employee → Email

Important: This email field is the source of truth for 2FA delivery and is not tied to the username/login field.


Final Result

The user is successfully logged into PatientNow Essentials.


Troubleshooting

Issue

Likely Cause

Resolution

Cannot log in

Incorrect username or password

Verify credentials or reset password

No verification code received

Incorrect or outdated email in Employee Profile

Verify and update email in Employee Profile

Verification code not received

Email filtered to Spam/Junk

Check Spam/Junk folders

Verification code delayed

Email delivery delay

Wait 1–2 minutes and request a new code

Code not working

Code expired (over 20 minutes)

Request a new code and enter promptly

Code not working

Using an older code

Use only the most recent code received

Prompt requests email

No email on file

Enter a valid email and continue

User entered incorrect email

Typo or incorrect entry

Restart login and enter correct email

User expects text message

SMS/text not supported

Inform user that verification is email only

Not prompted for 2FA

Login credentials not accepted

Resolve login issue first

2FA required every login

“Remember this device” not selected

Select “Remember this device” (30-day validity)

Still not receiving code

Incorrect email saved in profile

Update Employee Profile and retry login

Note: Most 2FA issues are caused by incorrect email addresses, delayed delivery, or expired codes rather than system errors.


FAQ

Q. Why is two-factor authentication important?
Two-factor authentication adds an extra layer of security by requiring a second verification step, helping protect accounts and sensitive data even if a password is compromised.

Q. Why did you make these changes?
We’ve made this update to strengthen account security and better protect sensitive client data, while aligning with industry best practices. This change also supports our commitment to maintaining SOC 2 compliance—an industry-recognized security standard required by many practices.

Q. Do I need to set anything up?
No. 2FA will be automatically enabled and managed for your account, no additional setup is required.

Q. How will I receive the verification code?
You will receive the verification code via email from ‘notices@envisionnow.com

Q. Can I receive the verification code via text message?
No. Verification codes by text message are not supported at this time.

Q. What email address will the verification code go to?
The verification code will be emailed to the email address listed in your Employee Profile.

Q. What if my Employee Profile is missing an email address?
Upon login, you will be prompted to enter the email address you’d like the verification code to be emailed to. This email address will be saved to your Employee Profile upon confirmation.

Q. Can I change the email address where the verification code will be sent to?
Yes. Remove or update the email address under your Employee Profile. Upon the next login, you will be prompted to either confirm or enter the new email address you’d like the verification code to be emailed to.

Q. Do I have to enter the verification code on every login?
No. You will only be prompted with two-factor authentication every 30 days (if you choose to remember the device) or upon logging into a new device.

Q. Can I adjust how often I’m prompted for 2FA if I want something other than 30 days?
No, the 2FA prompt frequency cannot be adjusted. The 30-day window is set to balance strong security with minimal disruption to your workflow.

Q. Does this apply to all users in my organization?
Yes. 2FA is enforced across all users to ensure consistent protection of your account and client data.

Did this answer your question?