mindora
All GuidesSettings

Security Settings

Change your password, enable two-factor authentication, manage active sessions, and enhance your account security.

5 min
Medium

What are Security Settings?

Security settings help you protect your Mindora account from unauthorized access. With tools like password management, two-factor authentication, auto-lock, session control, and access logs, you can keep your account security at the highest level.

How to Reach This Page

Follow these steps to reach security settings:

1

Open Profile Menu

Click the profile icon in the top right corner.

2

Go to Settings

Select "Settings" from the dropdown menu.

3

Open Security Tab

Click the "Security" tab on the Settings page.

Password Change

To change your password, you need to enter your current password, then type your new password and confirm it.

Tip
Password change is not available for users who signed up with Google. When you sign up with Google, you always log in with your Google account and no password is set. For more details about registration methods, see our Registration Guide.

Password Rules

  • Must be at least 12 characters long.
  • Must contain at least one uppercase letter (A-Z).
  • Must contain at least one lowercase letter (a-z).
  • Must contain at least one digit (0-9).
  • Cannot contain parts of your first name or email address.

Leaked Password Check

When creating a new password, it is checked against the "Have I Been Pwned" database. Passwords that have previously appeared in a data breach are rejected.

Tip
This password is not secure because it has appeared in previous data breaches. Please choose a stronger password.

Secure Storage

Passwords are never stored as plain text. They are hashed using the bcrypt algorithm with a minimum cost factor of 12, and only the hash value is stored in the database.

What Happens After Changing Your Password?

When your password is successfully changed, all your active sessions are automatically terminated for your security, and you will need to log in again. A notification email is also sent to your email address — so if you did not make this change, you can take action immediately.

Two-Factor Authentication (2FA)

Two-factor authentication adds an extra layer of security to your account. You can enable 2FA by setting up an authenticator app like Google Authenticator or Authy. Once enabled, you will need to enter a 6-digit code from the app in addition to your password at every login.

What Is an Authenticator App?

Authenticator apps generate temporary 6-digit codes that change every 30 seconds. Since these codes are only generated on your phone, they prevent unauthorized access even if your password is stolen.

Recommended Apps

Microsoft Authenticator

Easy to use with simple code management. Free for iOS and Android.

Google Authenticator

Simple and lightweight. Supports backup with your Google account. Free for iOS and Android.

Authy

Multi-device support and cloud backup. Your codes are preserved when switching phones.

How to Enable 2FA

1

Download one of the apps above on your phone (App Store or Google Play).

2

In Mindora, go to Settings → Account & Security.

3

Click "Start Setup". A QR code will appear on screen.

4

Open your authenticator app, tap "+" or "Add account", and scan the QR code with your phone's camera.

5

Enter the 6-digit code shown in the app into Mindora and click "Verify and Enable".

6

Save the recovery codes shown to you in a safe place. If you lose your phone, you can use these codes to access your account.

Disabling 2FA

We offer two options to disable 2FA:

1

With authenticator code

Enter the 6-digit code from your app. This is the quickest method if you have access to your authenticator app.

2

With recovery code

Enter one of your recovery codes along with your account password. The additional password is required for security: since recovery codes are static one-time codes, your password serves as an extra verification layer in case they are compromised.

Tip
We provide two methods so your account never gets locked out if you lose your phone or cannot access your authenticator app.

Recovery Codes

Recovery codes are one-time codes you can use when you lose access to your authenticator app. Each code can only be used once. Keep your codes in a safe place and do not share them with anyone.

Tip
When you disable and re-enable 2FA, a new QR code is generated. Make sure to remove the old Mindora code from your authenticator app, otherwise you'll see multiple Mindora codes and it may be hard to tell which one is current.

Clinical Privacy & Auto-Lock

The auto-lock feature protects your patient data by locking your screen after a certain period of inactivity. Enable it with the toggle and set the duration in minutes (between 1 and 120 minutes). When activated, the screen will dim after the set period and you will need to re-authenticate.

Tip
The recommended maximum duration per HIPAA standards is 15 minutes.

Active Sessions

You can view all active devices connected to your account. For each session, the browser name and version, operating system, location, and IP address are shown. The session start time and last activity time are also displayed.

  • The device you are currently using is marked with a "This Device" label.
  • If you see an unrecognized device, you can remotely log out using the "Log Out" button.
  • The "Log Out All Other Devices" button lets you terminate all sessions except your current device at once.

Devices currently logged into your account.

Chrome 144 · macOS 10.15.7 This Device

Istanbul, TR (88.241.x.x)

Session started: 3 Mar 2026, 09:00

Last active: Now

Safari 18 · iOS 17.4

Ankara, TR (176.23.x.x)

Session started: 2 Mar 2026, 14:30

Last active: 2 hours ago

Firefox 125 · Windows 11

Izmir, TR (92.44.x.x)

Session started: 1 Mar 2026, 10:15

Last active: Yesterday

Recent Access Logs

Recent access logs chronologically list all login, logout, and security events for your account. Each entry shows the date, device information (browser and operating system), IP address, and event type.

  • Events are color-coded by severity: green for successful actions, amber for warnings, and red for security issues.
  • The info button next to the title shows all event types and their descriptions.
  • By default, the last 20 records are shown. Use the "Show more" button to load older records.

Event Types

The following event types may appear in your access logs. Events are color-coded by severity:

Login & Session

User logged in.
New device login detected.
User logged out.
Session terminated remotely.
All sessions were terminated.

Security

Password was changed.
Two-step verification was enabled.
Two-step verification was disabled.
Verification code entered incorrectly.
Account locked due to too many failed login attempts.

Recent access events for your account.

DateDeviceIPEvent
3 Mar 2026, 09:41Chrome 144 · macOS 10.15.788.241.x.xUser logged in.
3 Mar 2026, 09:41Chrome 144 · macOS 10.15.788.241.x.xNew device login detected.
2 Mar 2026, 18:20Safari 18 · iOS 17.4176.23.x.xUser logged out.
1 Mar 2026, 14:00Firefox 125 · Windows 1192.44.x.xPassword was changed.
28 Feb 2026, 21:30Chrome 144 · Windows 1185.102.x.xVerification code entered incorrectly.

Tips & Best Practices

Tip
Make sure to enable two-factor authentication. It is the most effective way to prevent unauthorized access to your account.
Tip
Regularly check your active sessions. If you see an unrecognized device, immediately log out and change your password.
Tip
If you notice suspicious activity, use the "Log Out All Other Devices" button to terminate all sessions at once.
Tip
If you notice a suspicious login attempt in your access logs, immediately change your password and make sure 2FA is enabled.
Tip
We recommend using a password manager (1Password, Bitwarden, etc.) to generate strong and unique passwords.
Tip
Do not reuse passwords from other sites for your Mindora account. Set a unique password for each account.
Tip
If you work in a clinical environment, enable auto-lock. HIPAA standards recommend a maximum idle time of 15 minutes.