Recommended Free Tools
Use a long, unique password for your patient portal, turn on the strongest multifactor authentication (MFA) option it supports, and sign in only through a provider channel you have verified. Portal features differ by provider, so check its official instructions for setup and account recovery. Any health record you download also needs your protection.
Set up your portal account safely
- Open the official portal. Start from your provider’s official website or app. If an email or text prompted you to sign in, verify the request through a provider website or phone number you already know before entering your credentials. The Office of the National Coordinator for Health Information Technology (ONC) advises verifying the source before sharing personal or medical information. ONC consumer guidance
- Set a unique password. Choose one you do not use for email, banking, or any other account. A password manager with a generator can help create and store distinct credentials. NIST says verifiers should allow password managers and autofill, and notes that managers—particularly those with generators—can help people choose stronger passwords. NIST SP 800-63B, Revision 4
- Turn on MFA if it is available. Look in the portal’s account or security settings, then follow the provider’s instructions. Prefer a supported passkey or security key when offered; otherwise, enable the strongest available option, such as an authenticator code or approval prompt. Do not assume every portal supports every method.
- Check recovery details. Make sure the recovery email address and phone number are current. If the provider supplies recovery codes, follow its directions and store them separately from your password.
- Secure the device and end shared sessions. Use a passcode or screen lock on the phone or computer you use for the portal, and sign out when finished on a shared device. ONC identifies access controls and workstation security among safeguards that can help reduce unauthorized access. ONC security guidance
Choose a password that is long, unique, and practical
NIST SP 800-63B, Revision 4 (the 2025 edition), requires a minimum of 15 characters for passwords used as a single authentication factor. It permits a minimum of eight characters when a password is used only as part of MFA. Those are requirements for identity-system verifiers, not proof that a particular patient portal follows them. If the portal accepts a longer password, a long, memorable passphrase or a randomly generated password stored in a manager is a sensible choice.
Current NIST guidance does not require arbitrary recipes such as a particular mix of uppercase letters, digits, and symbols, and it says verifiers should not require routine password changes. Change your password promptly if you have evidence it may have been exposed; do not rely on a calendar rotation to make a reused or compromised password safe. The portal may have its own rules, so choose a password that meets its actual requirements.
Pick MFA by security, compatibility, and recovery
MFA asks for another authentication factor in addition to the password. The methods are not equally resistant to phishing: NIST says passwords and manually entered one-time codes are not phishing-resistant, while cryptographic authentication can be. A code or approval prompt still adds a login step if that is what your portal offers, but it should not be described as phishing-proof.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
| Option | What to consider |
|---|---|
| Passkey or security key | Cryptographic authentication can resist phishing. Confirm that the portal and your device support the specific method, and check how you would recover access if the device or key is lost. |
| Authenticator-app code or approval prompt | Useful as an additional step when supported, but it is not the same as phishing-resistant cryptographic authentication. Follow the provider’s setup and recovery instructions. |
| Text-message code | May be the available option on some portals. It adds a login step, but manually entered one-time codes are not phishing-resistant under NIST’s guidance. |
These are comparison points, not a list of methods every provider offers. ONC says safeguards for Blue Button access vary by the organization offering it; the same practical limitation applies when checking a portal’s own MFA choices. Use the provider’s official help page or verified support channel to confirm availability, enrollment, and recovery. Do not buy a hardware key until the provider confirms that its portal supports a compatible security-key flow.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Know what HIPAA does—and does not—protect
HIPAA generally requires covered providers and health plans to safeguard health information; its Security Rule addresses electronic protected health information. ONC describes safeguards that can include passwords or PINs, encryption, audit trails, and workstation security. But HIPAA protections do not automatically follow a copy of your record to every service you choose to use.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
If you download records or send them to another app or storage service, protect the copy with a password or encryption and review that service’s privacy terms. ONC notes that an organization outside HIPAA coverage may not be subject to the same rules. Its consumer guidance, last updated April 1, 2026, puts the online-sharing risk plainly: “Never post anything online that you don’t want made public.” ONC consumer guidance ONC portal FAQ
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Rank #3
If you think your password was exposed
- Go to the portal through the provider’s official website or app and change the password. NIST calls for a change when there is evidence that an authenticator has been compromised.
- Review account activity for unfamiliar sign-ins or changes if the portal provides that information.
- Contact the provider through a phone number or website you verify independently, especially if you cannot sign in or notice unauthorized changes.
- Update any other account where you reused the exposed password, starting with email, and give each account its own password.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




