Skip to content
Fullscript leaf logo
Create account
Fullscript logo
Fullscript leaf logo
  • Solutions
    • Plan care
      Lab testing Offer end-to-end diagnostics.
      Supplement catalog Recommend healthcare’s best.
      Clinical decision support Optimize your patients’ plans.
      Evidence-based templates Build complete plans quickly.
    • Deliver care
      Online plans Send individual and multi-patient plans.
      Wholesale ordering Dispense supplements from your clinic.
    • Engage patients
      Patient experience See how patients thrive on Fullscript.
      Adherence & insights Keep patients on track with less effort.
      Patient promotions Offer savings, engage patients in a few clicks.
    • IntegrationsSee all integrations
  • Resources
    • Learn
      How to use Fullscript Explore quick demos, articles, and more.
      Wellness blog Education for practitioners and patients.
      Webinars 100+ recordings of practitioner discussions.
      Protocols Our library of evidence-based protocols.
      Clinical evidence Studies that support the Fullscript platform.
      Practice resources Handouts, promotional tools, and more.
      Ingredient library Decision support for supplement ingredients.
    • Featured
      lets make healthcare whole kyle feature image
      Let’s Make Healthcare Whole

      Learn how Fullscript is making whole person care more attainable, scalable, and impactful.

  • Pricing
Sign in Create account Book a demo Sign in
Product
—

Protecting What Matters Most – Your Practice and Your Patients

Updated on February 10, 2025 | Published on February 10, 2025
Fact checked
  1. Wellness blog
  2. Protecting What Matters Most – Your Practice an...

As your trusted partner in whole person care, Fullscript has always made protecting practitioner and patient data a top priority. This means constantly looking at our platform and implementing best-in-class security measures over the years. Fullscript is committed to going above and beyond to help keep the information from you and your patients safe. 

Here’s a quick look at some of the standards and protocols we’ve committed to: 

  • SOC 2 Type II Compliance: Demonstrating our commitment to managing your data securely and protecting the privacy of sensitive information.
  • PCI/DSS Compliance: Ensuring secure payment processing and protecting financial information.
  • Independent HIPAA Assessments: Regular evaluations to ensure we meet HIPAA standards for protecting patient health information.
  • Regular Third-Party Security Testing: Partnering with independent experts to identify and mitigate potential vulnerabilities.

The pivot to mandatory Multi-Factor Authentication (MFA)

As part of our mission to go above and beyond modern security protocols, Fullscript is introducing mandatory multi-factor authentication (MFA) for all practitioner and clerk accounts by early 2025.This added layer of protection greatly enhances account security and further safeguards your practice and patient data.

MFA is a proactive step forward, aligning with industry best practices and showing our commitment to being a responsible partner for your practice.  MFA has been available to you on Fullscript for some time, but is now mandated We’ve added functionality to the MFA experience that maintains the high security standards, while providing customers with convenience and speed, including the ability to verify with multiple methods like email and text message, as well as a “trust this device” option — limiting the need to verify every time.

MFA: A small step with big security benefits 

Multi-factor authentication (MFA) significantly reduces the risk of unauthorized account access, even if your password becomes compromised outside of our system. It combines something you know (your password) with something you have (a device), adding an additional barrier for potential threats.

According to Microsoft:

  • Over 99.99% of MFA-enabled accounts remain secure during security investigations.
  • MFA reduces the risk of compromise by over 99%, even in cases where credentials have been leaked.

By enabling MFA, you’re making a small change that delivers major security benefits for you and your patients.

FAQ: Fullscript’s New MFA Requirement

What is MFA, and how does it work?

MFA is a Multi-Factor Authentication process. After entering your password, you’ll verify your identity using a unique code sent to your mobile device or verification app. This will be prompted instantly upon sign in, and the entire verification process takes seconds.

How long does it take to set up?

Setting up MFA typically takes less than two minutes. The process is simple and guided step-by-step within your Fullscript account. For more information, see our step-by-step guide.

What happens if I don’t set up MFA by my cutoff date?

In the New Year, we’ll  be rolling this mandatory requirement out to our customers. Once it becomes mandatory for you, you won’t be able to access your Fullscript account until MFA is enabled. We will notify you by email to notify you of your enrollment date. 

Can I opt out of MFA?

MFA will be mandatory for all Fullscript practitioner and clerk accounts. We are taking proactive measures to ensure we’re aligned with robust security standards, keeping the protection of sensitive practitioner and patient data our top priority. 

What if I lose access to my MFA device?

If you lose access to your MFA device, you can recover your account by following the recovery steps provided in the login screen or contacting our support team.

Can I set something up to avoid going through authentication every time I log in?

Yes, Fullscript offers a “trust this device” option. When enabled, this feature allows you to skip the MFA process on that device in the future. However, you will still need to log in with your password to maintain security.

What types of MFA options are available?

Fullscript supports two MFA methods, including:

  1. SMS: We’ll send a text with a verification code to the number associated with the account. 
  2. Verification app (recommended): Download a verification app, such as Google Authenticator, Microsoft Authenticator, LastPass Authenticator, Twilio Authy Authenticator, etc. to receive one-time login codes.
  3. Email: You’ll receive a one-time code to the primary email associated with your account. This code will need to be entered into the authenticator when logging in to Fullscript

Will it be mandatory for patients to set up MFA?

Patients currently have access to MFA. We’re starting this mandatory process with our practitioner and clerk customers first. 

Can I set up 2-step verification for my staff or my patients?

No, each user — whether it’s a sub-practitioner or a clerk using a staff account — will each need to set up MFA for their own accounts.

How do I enable MFA on my Fullscript account?

Follow the step-by-step instructions in our support article.

Other best practices for securing your accounts

Here are some tips for enhancing security across all your online accounts, including Fullscript:

  1. Use strong password strategies: Make passwords long, random, and unique. Avoid reusing passwords across multiple platforms. We recommend leveraging a password manager to help you use and remember strong passwords.
  2. Enable MFA Everywhere: Activate MFA for any account that offers it, especially email, financial, and healthcare accounts.
  3. Keep Software Updated: Regularly update your device and application software to address security vulnerabilities.
  4. Beware of Phishing Attempts: Never click on suspicious links or provide login credentials to unverified sources.
  5. Monitor Your Accounts: Regularly review your account activity for any unusual behavior.

For more guidance, visit CISA’s guide to MFA.

Need help? If you have questions or need technical support for enabling MFA on your Fullscript account, visit our support article or contact our support team for assistance.

Together, we can keep your information secure

Thank you for taking these steps with us to help ensure you and your patients’ information stays protected. We’re always looking for ways to stay aligned with the latest security standards and will keep you informed along the way. 

Learn more about enabling multi-factor authentication (MFA) in your Fullscript account

Learn more

Disclaimer

The information in this article is designed for educational purposes only and is not intended to be a substitute for informed medical advice or care. This information should not be used to diagnose or treat any health problems or illnesses without consulting a doctor. Consult with a health care practitioner before relying on any information in this article or on this website.

SHARE THIS POST
  • Print
  • Email
  • Facebook
  • LinkedIn
  • Twitter
  • Pinterest

More resources

Protocols
Practice resources
Ingredient library
Webinars

Make healthcare whole with Fullscript

Join 100,000+ providers building the future of whole person care today.

Create free account

Fullscript content philosophy

At Fullscript, we are committed to curating accurate, and reliable educational content for providers and patients alike. Our educational offerings cover a broad range of topics related to whole person care, such as supplement ingredients, diet, lifestyle, and health conditions.

Medically reviewed by expert practitioners and our internal Medical Advisory Team, all Fullscript content adheres to the following guidelines:

  1. In order to provide unbiased and transparent education, information is based on a research review and obtained from trustworthy sources, such as peer-reviewed articles and government websites. All medical statements are linked to the original reference and all sources of information are disclosed within the article.
  2. Information about supplements is always based on ingredients. No specific products are mentioned or promoted within educational content.
  3. A strict policy against plagiarism is maintained; all our content is unique, curated by our team of writers and editors at Fullscript. Attribution to individual writers and editors is clearly stated in each article.
  4. Resources for patients are intended to be educational and do not replace the relationship between health practitioners and patients. In all content, we clearly recommend that readers refer back to their healthcare practitioners for all health-related questions.
  5. All content is updated on a regular basis to account for new research and industry trends, and the last update date is listed at the top of every article.
  6. Potential conflicts of interest are clearly disclosed.
Learn more

The healthiest cookies you’ll choose today

Our website uses cookies to collect useful information that lets us and our partners support basic functionality, analyze visitor traffic, deliver a better user experience, and provide ads tailored to your interests. Agreeing to the use of cookies is your choice. Learn more

Fullscript leaf icon
Platform
  • What’s new
  • Integrations
  • Testimonials
  • Catalog
Company
  • About us
  • Blog
  • Why Fullscript
  • Careers
  • Partnerships
  • Quality program
Help
  • Book a demo
  • Support Center
  • Provider FAQs
  • Patient FAQ
  • Contact us
  • Security
Developers
  • Engineering at Fullscript
  • API

© Fullscript 2025. All rights reserved.

*These statements have not been evaluated by the Food and Drug Administration. These products are not intended to diagnose, treat, cure, or prevent any disease.

  • Privacy Statement
  • Terms of Service
  • Accessibility Policy
  • Customer Support Policy
  • Acceptable Use Policy
  • Privacy Rights Notice
  • Auto Refill Terms and Conditions
  • Consumer Health Data Privacy Notice
American flag - toggles to show american specific contentUS
Canadian flag - toggles to show canada specific contentCanada