Skip to main content
ImaraCare uses email one-time passwords (OTP) to satisfy HIPAA § 164.312(d) — Person or Entity Authentication. No authenticator app or QR code is required.

Who must verify

Manager and Administrator roles must complete email OTP verification. Staff roles are not required to verify by default.

How it works

1

Sign in normally

Enter your email address and password at the sign-in screen.
2

Check your email

ImaraCare sends a 6-digit code to your registered email address.
3

Enter the code

Type the code on the verification screen. The code expires after 10 minutes.
4

Access granted

You are signed in. Verification is valid for the remainder of that workday (8 hours) — you will not be asked again until your next session.

Code did not arrive?

  1. Check your spam or junk folder
  2. Wait 30–60 seconds and click Resend code on the verification screen
  3. If the problem persists, contact your Administrator or support

Session expiry

  • Inactivity timeout: 45 minutes — you are signed out automatically if the app is idle
  • After sign-out, sign in again; a new OTP is required if your 8-hour window has elapsed

Administrators

Administrators cannot disable email OTP for Manager or Administrator roles — it is required by HIPAA policy. Staff OTP is not currently enforced. See Security and privacy for session termination and other access controls.