Skip to main content

Setting up two-factor authentication

Set up two-factor authentication using an authenticator app to secure your Rivvi account and protect patient data.

Written by Nathan Hayman

Quick Answer

Two-factor authentication (2FA) is required for all Rivvi users and is set up automatically during your first login. If you need to set it up again on a new device or after a reset, go to Settings → Personal → Security.


🔒 Security Requirement

2FA is mandatory for all Rivvi users to protect sensitive patient data and maintain HIPAA compliance. It cannot be disabled.


Who This Is For

  • Users setting up 2FA for the first time

  • Users who need to set up 2FA on a new device

  • Users who lost access to their authenticator app

  • Admins helping team members with 2FA issues


What You'll Learn

  • What two-factor authentication is and why it's required

  • How to set up an authenticator app

  • How to save and use backup codes

  • How to set up 2FA on a new device

  • Troubleshooting 2FA issues


What is Two-Factor Authentication?

Two-factor authentication (2FA) adds an extra layer of security to your account by requiring two things to log in:

  1. Something you know: Your password

  2. Something you have: Your phone with an authenticator app

Even if someone steals your password, they can't access your account without your phone.

[INSERT IMAGE: Diagram showing password + phone = secure login]


Why Rivvi Requires 2FA

  • HIPAA Compliance: Required for protecting electronic Protected Health Information (ePHI)

  • Patient Data Security: Prevents unauthorized access to sensitive medical records

  • Industry Best Practice: Healthcare organizations must implement multi-factor authentication

  • Breach Prevention: 2FA stops 99.9% of automated attacks

Note

Rivvi uses Time-based One-Time Passwords (TOTP), which is more secure than SMS-based authentication.


Choosing an Authenticator App

You'll need an authenticator app on your smartphone. Here are the most popular options:

App

Platforms

Features

Best For

Google Authenticator

iOS, Android

Simple, free

Most users

Microsoft Authenticator

iOS, Android

Cloud sync, free

Microsoft users

Authy

iOS, Android, Desktop

Multi-device, cloud backup

Multiple devices

1Password

iOS, Android, Desktop

Password manager included

All-in-one solution

💡 Tip

Already using a password manager? Many password managers (like 1Password and Bitwarden) include built-in authenticator functionality.


Setting Up 2FA (First Time)

2FA is set up automatically during your first login. Here's what happens:

Step 1: Download an Authenticator App

If you don't have one yet:

  1. Open your phone's app store

  2. Search for "Google Authenticator" or "Microsoft Authenticator"

  3. Download and install the app

[INSERT IMAGE: App store showing Google Authenticator]

Step 2: Scan the QR Code

  1. After creating your password, Rivvi shows you a QR code

  2. Open your authenticator app

  3. Tap Add Account or +

  4. Tap Scan QR Code

  5. Point your camera at the QR code on your screen

[INSERT IMAGE: Phone camera scanning QR code on computer screen]

Step 3: Enter the 6-Digit Code

  1. Your authenticator app will display a 6-digit code

  2. Enter this code in Rivvi

  3. Click Verify or Enable 2FA

[INSERT IMAGE: Authenticator app showing 6-digit code with countdown timer]

Step 4: Save Your Backup Codes

This is critical - don't skip it!

  1. Rivvi displays 10 backup codes

  2. Click Download or Copy

  3. Store them securely:

    • Save in your password manager

    • Print and store in a safe place

    • Email to yourself (encrypted)

[INSERT IMAGE: Backup codes screen with 10 codes displayed]

⚠️ Important

Each backup code can only be used once. If you use all 10, generate new ones immediately.


Manual Setup (Can't Scan QR Code?)

If you can't scan the QR code:

  1. Click Can't scan? or Enter manually

  2. Rivvi shows a setup key (long alphanumeric string)

  3. In your authenticator app, choose Enter key manually

  4. Enter these details:

    • Account name: Rivvi (or your email)

    • Key: [paste the setup key]

    • Type: Time-based

  5. Save

  6. Enter the 6-digit code shown in your app

[INSERT IMAGE: Manual setup screen showing setup key]


Setting Up 2FA on a New Device

If you got a new phone or need to set up 2FA again:

Option 1: Use a Backup Code (Recommended)

  1. Log in with your username and password

  2. At the 2FA screen, click Use backup code

  3. Enter one of your saved backup codes

  4. You'll be logged in

  5. Go to Settings → Personal → Security

  6. Click Reset 2FA or Set up new device

  7. Follow the QR code setup process again

  8. Save your new backup codes

[INSERT IMAGE: 2FA login screen with "Use backup code" link]

Option 2: Contact Support

If you don't have backup codes:

  1. Verify your identity (name, email, organization, etc.)

  2. Support will reset your 2FA

  3. This takes 24-48 hours for security reasons

  4. You'll receive an email when it's complete


Using 2FA When Logging In

Every time you log in after the first time:

  1. Enter your username

  2. Enter your password

  3. Open your authenticator app

  4. Enter the current 6-digit code

  5. Click Log In

[INSERT IMAGE: Login flow showing all 3 steps]

How Long Do Codes Last?

  • Each code is valid for 30 seconds

  • A countdown timer shows time remaining

  • If you enter an expired code, wait for a new one

  • Don't try to "race" the timer - wait for a fresh code

[INSERT IMAGE: Authenticator showing countdown timer at 25 seconds]


Using Backup Codes

You should use backup codes only when:

  • ❌ You lost your phone

  • ❌ Your phone is broken/dead

  • ❌ You can't access your authenticator app

  • ❌ You're setting up a new device

How to use a backup code:

  1. At the 2FA login screen, click Use backup code

  2. Enter one of your saved codes exactly as shown

  3. Click Verify

  4. You'll be logged in

⚠️ Important

After using a backup code, set up 2FA on your new device immediately and generate new backup codes.

[INSERT IMAGE: Backup code entry screen]


Generating New Backup Codes

You should generate new backup codes if:

  • You've used several of your original codes

  • You think your codes may have been compromised

  • You want to refresh them for security

To generate new codes:

  1. Log in to Rivvi

  2. Go to Settings → Personal → Security

  3. Click Generate new backup codes

  4. Your old codes will be invalidated

  5. Save the new codes securely

[INSERT IMAGE: Security settings page with "Generate new backup codes" button]


Troubleshooting 2FA

"Invalid code" Error

Possible causes:

Issue

Solution

Code expired

Wait for a new code (30 seconds)

Phone time wrong

Enable "automatic date/time" in phone settings

Wrong account

Check you're using the Rivvi entry in your app

Typo

Enter all 6 digits carefully

[INSERT IMAGE: Phone settings showing automatic date/time enabled]

Can't Scan QR Code

Try these solutions:

  1. Increase screen brightness

  2. Hold phone closer/farther from screen

  3. Use manual entry instead

  4. Try a different device's camera

  5. Take a screenshot and scan from another device

Authenticator App Not Working

  1. Force close and reopen the app

  2. Restart your phone

  3. Check for app updates

  4. Reinstall the authenticator app (you'll need backup codes)


Best Practices

Securing Your Backup Codes

Save in password manager (encrypted)
Print and store in safe (physical backup)
Save in multiple locations (redundancy)

Never share backup codes with anyone
Don't store in plain text files
Don't email without encryption

Multiple Devices

Set up 2FA on multiple devices if your authenticator supports it (Authy, 1Password)
Keep backup codes accessible on all devices
Test codes regularly to ensure they work

Regular Maintenance

Test backup codes once per quarter
Generate new backup codes after using any
Update authenticator app regularly
Document where codes are stored for emergencies


Common Questions

Q: Can I disable 2FA?

A: No. 2FA is required for all Rivvi users and cannot be disabled due to HIPAA compliance requirements.

Q: Can I use SMS instead of an authenticator app?

A: No. SMS-based 2FA is not secure enough for healthcare data. Rivvi requires authenticator apps.

Q: What if I have multiple Rivvi accounts?

A: Each account needs its own 2FA setup in your authenticator app. They'll appear as separate entries.

Q: Can I use the same authenticator for multiple healthcare apps?

A: Yes! Your authenticator app can hold codes for unlimited accounts.

Q: What happens if I don't set up 2FA?

A: You cannot skip 2FA setup. It's required during first login and you cannot access Rivvi without it.

Q: How do backup codes work?

A: Each backup code is a one-time-use 8-16 character code that replaces your 6-digit authenticator code. Once used, it's invalid.

Q: My phone died and I don't have backup codes. What do I do?

A: Contact support immediately. They can reset your 2FA after verifying your identity (24-48 hour process).


Next Steps

Now that 2FA is set up:


Need Help?

If you're having trouble with 2FA:

  • 💬 Chat with support using the messenger

  • 📧 Email: support@rivvi.ai

  • 📞 Call: [Support phone number]

  • 🕐 Hours: Monday-Friday, 9am-5pm EST

Did this answer your question?