Sign-in & security
BirthTracks protects the records you hold, so signing in is built to be both easy day-to-day and hard for anyone else to get through. This page covers every way you can sign in and the security controls on your account.
Signing in with email and password
Section titled “Signing in with email and password”The standard path is your email address and password on the Log in to your account page. If you’ve forgotten your password, choose Forgot your password? on that page and we’ll email you a reset link.
Changing your password
Section titled “Changing your password”Change your password from the Password page — open the account menu (your initials at the top right) and choose Password:
- Enter your Current password.
- Enter a New password and type it again in Confirm new password.
- Choose Update password.
If you signed up with Google, your account has no password yet, so the page shows You sign in with Google instead of the form. To add a password, sign out and use Forgot your password? on the log-in page — you can keep using Google afterwards.
Continue with Google
Section titled “Continue with Google”Where Google sign-in is available, a Continue with Google button appears above the email-and-password form on the log-in and sign-up pages. It’s an alternative to a password, not a replacement for your account — the same account works either way:
- New to BirthTracks? Continuing with a Google account we haven’t seen creates your account and practice in one click, with no password — see Sign up with Google.
- Already have an account with that email? Google is linked to it and you’re signed in. If that account has multi-factor authentication turned on, it isn’t linked automatically: log in with your password, then use Connect on your Profile (below).
- Multi-factor authentication still applies. If your account has MFA turned on, you’re asked for your code after Google, exactly as after a password.
You manage the Google link from Profile (in the account menu — your initials at the top right), under Connected accounts:
- If Google isn’t linked, the row shows Not connected; choose Connect to link it.
- If it’s linked, the row shows Connected, and you can choose Disconnect.
- If Google sign-in isn’t available, the row shows Unavailable instead of Connect.
Passkeys
Section titled “Passkeys”A passkey lets you sign in with your device instead of a password — Face ID, Touch ID, Windows Hello, or a hardware security key. A passkey stays on your device and only works on this site, so it can’t be phished or replayed.
Signing in with a passkey
Section titled “Signing in with a passkey”Once you’ve added a passkey, choose Sign in with a passkey on the log-in page and follow your device’s prompt — no email or password needed. The button only appears in browsers that can use passkeys; if you don’t see it, sign in with your password instead.
Managing your passkeys
Section titled “Managing your passkeys”Passkeys are available to every account. You manage them on the Passkeys page — open the account menu (your initials at the top right) and choose Passkeys:
- Add passkey — give it a name (for example, “MacBook Touch ID”) and follow your device’s prompt.
- Each passkey shows the device it lives on and when it was last used.
- Remove a passkey you no longer use; you’ll no longer be able to sign in with it.
Multi-factor authentication keeps working alongside a passkey.
Multi-factor authentication
Section titled “Multi-factor authentication”Multi-factor authentication (MFA), also called two-factor authentication (2FA), adds a one-time code from an authenticator app on top of your password. It’s available to every account.
Whether MFA is required isn’t a practice setting — your practice admin can’t turn it on or off. It’s a BirthTracks-wide policy that applies to particular roles, and it isn’t required unless BirthTracks has switched it on for your role.
Set it up from the Multi-factor authentication (MFA) page — open the account menu (your initials at the top right) and choose MFA (if you signed up with Google, see the note above about setting a password first):
- Choose Enable.
- Scan the QR code with your authenticator app, or enter the Setup key by hand.
- Enter the generated Code and choose Confirm.
Once enabled, store the recovery codes we show you somewhere safe — they let you back in if you lose your authenticator device. You can Show recovery codes, Regenerate recovery codes, or Disable MFA from the same page.
When your role requires multi-factor authentication and you haven’t set any up, you’ll be sent to this page to set it up before you can continue. A registered passkey satisfies that requirement too, so you can choose Set up a passkey instead.
Signing in with MFA turned on
Section titled “Signing in with MFA turned on”Once MFA is on, after you sign in with your password (or with Google) you’ll see the Multi-factor authentication screen: enter the Code from your authenticator app and choose Log in. Lost your device? Choose Use a recovery code and enter one of your recovery codes instead.
Confirm multi-factor authentication
Section titled “Confirm multi-factor authentication”If your role requires MFA and you signed in this session without using your second factor — for example, you have only a passkey but signed in with your password — you’ll see Confirm multi-factor authentication before you can reach patient data. Choose Use a passkey, or enter your Authenticator code and choose Continue; you’re then taken on to the page you were opening. Recovery codes aren’t accepted on this screen. Signing in with a passkey in the first place counts as your second factor, so you won’t see this screen then.
Automatic sign-out when idle
Section titled “Automatic sign-out when idle”For safety on shared and unattended computers, BirthTracks signs you out after 15 minutes of inactivity. Sign back in to pick up where you left off. This is separate from staying signed in on a device you trust.