Security Settings
Change your password, enable two-factor authentication, manage active sessions, and enhance your account security.
What are Security Settings?
Security settings help you protect your Mindora account from unauthorized access. With tools like password management, two-factor authentication, auto-lock, session control, and access logs, you can keep your account security at the highest level.
How to Reach This Page
Follow these steps to reach security settings:
Open Profile Menu
Click the profile icon in the top right corner.
Go to Settings
Select "Settings" from the dropdown menu.
Open Security Tab
Click the "Security" tab on the Settings page.
Password Change
To change your password, you need to enter your current password, then type your new password and confirm it.
Password Rules
- Must be at least 12 characters long.
- Must contain at least one uppercase letter (A-Z).
- Must contain at least one lowercase letter (a-z).
- Must contain at least one digit (0-9).
- Cannot contain parts of your first name or email address.
Leaked Password Check
When creating a new password, it is checked against the "Have I Been Pwned" database. Passwords that have previously appeared in a data breach are rejected.
Secure Storage
Passwords are never stored as plain text. They are hashed using the bcrypt algorithm with a minimum cost factor of 12, and only the hash value is stored in the database.
What Happens After Changing Your Password?
When your password is successfully changed, all your active sessions are automatically terminated for your security, and you will need to log in again. A notification email is also sent to your email address — so if you did not make this change, you can take action immediately.
Two-Factor Authentication (2FA)
Two-factor authentication adds an extra layer of security to your account. You can enable 2FA by setting up an authenticator app like Google Authenticator or Authy. Once enabled, you will need to enter a 6-digit code from the app in addition to your password at every login.
What Is an Authenticator App?
Authenticator apps generate temporary 6-digit codes that change every 30 seconds. Since these codes are only generated on your phone, they prevent unauthorized access even if your password is stolen.
Recommended Apps
Microsoft Authenticator
Easy to use with simple code management. Free for iOS and Android.
Google Authenticator
Simple and lightweight. Supports backup with your Google account. Free for iOS and Android.
Authy
Multi-device support and cloud backup. Your codes are preserved when switching phones.
How to Enable 2FA
Download one of the apps above on your phone (App Store or Google Play).
In Mindora, go to Settings → Account & Security.
Click "Start Setup". A QR code will appear on screen.
Open your authenticator app, tap "+" or "Add account", and scan the QR code with your phone's camera.
Enter the 6-digit code shown in the app into Mindora and click "Verify and Enable".
Save the recovery codes shown to you in a safe place. If you lose your phone, you can use these codes to access your account.
Disabling 2FA
We offer two options to disable 2FA:
With authenticator code
Enter the 6-digit code from your app. This is the quickest method if you have access to your authenticator app.
With recovery code
Enter one of your recovery codes along with your account password. The additional password is required for security: since recovery codes are static one-time codes, your password serves as an extra verification layer in case they are compromised.
Recovery Codes
Recovery codes are one-time codes you can use when you lose access to your authenticator app. Each code can only be used once. Keep your codes in a safe place and do not share them with anyone.
Clinical Privacy & Auto-Lock
The auto-lock feature protects your patient data by locking your screen after a certain period of inactivity. Enable it with the toggle and set the duration in minutes (between 1 and 120 minutes). When activated, the screen will dim after the set period and you will need to re-authenticate.
Active Sessions
You can view all active devices connected to your account. For each session, the browser name and version, operating system, location, and IP address are shown. The session start time and last activity time are also displayed.
- The device you are currently using is marked with a "This Device" label.
- If you see an unrecognized device, you can remotely log out using the "Log Out" button.
- The "Log Out All Other Devices" button lets you terminate all sessions except your current device at once.
Devices currently logged into your account.
Recent Access Logs
Recent access logs chronologically list all login, logout, and security events for your account. Each entry shows the date, device information (browser and operating system), IP address, and event type.
- Events are color-coded by severity: green for successful actions, amber for warnings, and red for security issues.
- The info button next to the title shows all event types and their descriptions.
- By default, the last 20 records are shown. Use the "Show more" button to load older records.
Event Types
The following event types may appear in your access logs. Events are color-coded by severity:
Login & Session
Security
Recent access events for your account.
| Date | Device | IP | Event |
|---|---|---|---|
| 3 Mar 2026, 09:41 | Chrome 144 · macOS 10.15.7 | 88.241.x.x | User logged in. |
| 3 Mar 2026, 09:41 | Chrome 144 · macOS 10.15.7 | 88.241.x.x | New device login detected. |
| 2 Mar 2026, 18:20 | Safari 18 · iOS 17.4 | 176.23.x.x | User logged out. |
| 1 Mar 2026, 14:00 | Firefox 125 · Windows 11 | 92.44.x.x | Password was changed. |
| 28 Feb 2026, 21:30 | Chrome 144 · Windows 11 | 85.102.x.x | Verification code entered incorrectly. |