NHS Mail enhanced security live

MFA starts for all NHS Mail users

  • Published

NHS England have launched Multi-Factor Authentication (MFA) for all NHS Mail users.

For all Providers with existing NHSmail accounts, from mid August users will have received a notification asking them to register an MFA authentication method when logging to their account.

By 2 September, if your MFA has not been enrolled in, access to NHSmail will change meaning:

  • Enhanced password – minimum of 20 characters.
  • Security measures introduced: not having persistent browsing sessions
  • Restrictions on sign in frequency.
  • Password expiring every 90 days

For advice click below, and do contact [email protected] with any queries and we will signpost you to the best support

MFA User Frequently Asked Questions (FAQs) – NHSmail Support

Need digital advice for your provision? Find our Surrey Digital Security Protection Toolkit Team upcoming Autumn in-person events and webinars here – scroll down to ‘events.’

*Credit:unsplash/Mariia Shalabaieva