Historically, login break-ins all start the same way: a password that leaked from another website, reused on other websites. The steps below take about ten minutes and close that door.
1. Turn on two-factor authentication
This is the one step that makes a leaked password useless on its own. Each time you sign in, SeriousMD also asks for a code from the Google Authenticator app or from your email or SMS.
Go to Settings > Security > Login and Security, then click Configure under Two Factor Authentication.
2. Use a password you use nowhere else
If your SeriousMD password is also your Facebook, Gmail or online-shopping password, please change it today. When any of those sites leaks, yours leaks with it.
Make it long. Three or four unrelated words are easier to remember and harder to guess than one word with a number at the end. A password manager (the one built into your phone or browser is fine) will remember it for you.
3. Protect the email on your account
Your login code and your password reset both go to the email on your SeriousMD account. If someone gets into that inbox, they can get into everything.
Turn on 2-step verification on that email (Gmail and Yahoo both offer it). Better still, use an email address you only use for SeriousMD.
â
4. Check whether your email has been in a leak
Type your email into haveibeenpwned.com. It is a free service that lists the data leaks an email address has appeared in.
If it lists anything, change the passwords you were using around that time, starting with your email account and SeriousMD. If it lists "Stealer logs," a computer you used had password-stealing malware at some point: change every password saved in that browser and have the machine scanned.
5. The login code and Trusted Devices
When you sign in on the web from a device SeriousMD has not seen before, a one-time code is emailed to you. This used to happen only for logins from outside the Philippines. Now, it happens everywhere, because attackers can appear to be in the Philippines too.
You enter the code once per device. Then go to Settings > Security > Trusted Devices and trust your own laptop, phone and tablet so they are not asked again.
â ď¸ Do not trust a shared computer. Anyone who sits at it after you would skip the code.
6. Staff get their own accounts
Your secretary and nurses should never sign in with your email and password. Add them as sub-users instead (Settings > Security > Sub-Users): they get their own login, you choose what they can see and do, and if one of them leaves you remove one account instead of changing your own password.
7. On shared and clinic computers
Log out when you leave, and do not tick "remember me" or save the password in the browser.
Keep Windows or macOS updated and run an antivirus scan now and then. Malware on a clinic PC copies every password saved in its browser, and that is where many leaked passwords come from.
Do not install cracked software or browser extensions you do not recognise on a computer that touches patient records.
8. Signs something is wrong, and what to do
A "new login" email or a login code you did not ask for means someone has your password. Change it right away and message us in the app so we can check the account with you.
â Short version: turn on 2FA, use a password you use nowhere else, trust only your own devices, and give staff their own accounts.


