> ## Documentation Index
> Fetch the complete documentation index at: https://docs.imaracare.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-factor authentication

> Email one-time password verification for Managers and Administrators in ImaraCare.

ImaraCare uses **email one-time passwords (OTP)** to satisfy HIPAA § 164.312(d) — Person or Entity Authentication. No authenticator app or QR code is required.

## Who must verify

**Manager** and **Administrator** roles must complete email OTP verification. Staff roles are not required to verify by default.

## How it works

<Steps>
  <Step title="Sign in normally">
    Enter your email address and password at the sign-in screen.
  </Step>

  <Step title="Check your email">
    ImaraCare sends a **6-digit code** to your registered email address.
  </Step>

  <Step title="Enter the code">
    Type the code on the verification screen. The code expires after **10 minutes**.
  </Step>

  <Step title="Access granted">
    You are signed in. Verification is valid for the remainder of that workday (**8 hours**) — you will not be asked again until your next session.
  </Step>
</Steps>

## Code did not arrive?

1. Check your spam or junk folder
2. Wait 30–60 seconds and click **Resend code** on the verification screen
3. If the problem persists, contact your Administrator or [support](/help/contact-support)

## Session expiry

* Inactivity timeout: **45 minutes** — you are signed out automatically if the app is idle
* After sign-out, sign in again; a new OTP is required if your 8-hour window has elapsed

## Administrators

Administrators cannot disable email OTP for Manager or Administrator roles — it is required by HIPAA policy. Staff OTP is not currently enforced.

See [Security and privacy](/account/security) for session termination and other access controls.
