Zanda Health

Zanda Account Security: Passwords, Password Managers, 2FA

A password manager and two-factor authentication are key habits that keep every account you have secure, not only your Zanda account. Here's why each matters, and how to set them up.

This article covers key habits that keep your Zanda account secure: using a unique password, using a password manager, and turning on two-factor authentication (2FA). A weak or reused password puts your account at risk, and a password manager is what makes doing this properly realistic: it remembers and types a different, strong password for every account for you, so you get more security and less hassle, not a trade-off between them. These practices apply to every account you have online, not just Zanda: your email, your bank, your other software, all of it.

Use a unique password

Use a different password for every account, and make each one long and complex: a mix of uppercase and lowercase letters, numbers, and special characters. A long, random password is far harder to guess or crack than a short, familiar one.

Zanda stores your password as a one-way hash: even if someone were to gain unauthorized access to our systems, they could not recover your actual password from it, and neither can anyone at Zanda. Not every service takes the same approach, though, and that is exactly why reusing a password is risky: if another service you use stores passwords less carefully and is breached, your password can leak in a readable form, and attackers will try that same password and email address on other accounts, a technique called credential stuffing. One breach anywhere can then lead to a compromised account everywhere you used that password, Zanda included.

A unique password for every account closes that door. The easiest way to keep a different, long, complex password for every account is to let a password manager generate and remember it for you.

The same principle applies to team accounts: each team member should have their own Zanda login rather than sharing one user account among several staff. There’s no cost reason to share one, either: a Zanda subscription is priced by active practitioner profile, not by user login, so adding an account for each person doesn’t add to your subscription. A shared login means a shared password, which spreads the risk of exposure across everyone who uses it, and it removes any way to tell which team member took a given action. It also works against two-factor authentication: the verification code or authenticator app usually belongs to one person’s device. Everyone else sharing that login either can’t complete 2FA themselves or has to go through that one person, undercutting much of what 2FA is meant to protect. Set up a separate user account for each person in User Management instead.

Use two-factor authentication

Two-factor authentication (2FA) adds a second check beyond your password: a code from an authenticator app, in addition to something you know.

Here’s why that matters. Say an attacker tricks you into entering your password on a fake page made to look like the Zanda login screen, a phishing attack. Without 2FA, they now have everything they need to log in as you. With 2FA turned on, your password alone is not enough: they also need the code from your authenticator app, which they do not have access to. Your account stays protected even after your password is exposed.

See Activating Two-Factor Authentication for how to turn it on for your Zanda account.

Use a password manager

A password manager generates a long, random, unique password for every account, stores it in an encrypted vault, and fills it in for you when you log in. You only need to remember one master password. This is what makes using a unique password for every account realistic: remembering dozens of strong passwords by hand is not.

A password manager also makes 2FA far more convenient. Many password managers can generate the time-based codes (TOTP) that 2FA needs, right alongside your password. Instead of manually typing a 2FA code from a separate authenticator app, the password manager generates it and can fill it in for you automatically.

Look for a password manager that works across every device you use (phone and computer) and every browser. When it does, that convenience, strong passwords and automatic 2FA codes alike, follows you everywhere, not only on the device where you set it up.

Support for TOTP generation varies by provider and by plan, and it changes often, so check the current details before you choose. Moving your vault to a different password manager later is a hassle, so it is worth choosing one that supports 2FA code generation and autofill from the start rather than having to switch once you realize it does not. As of this writing:

  • Apple Passwords (built into iPhone, iPad, and Mac): free, generates 2FA codes, and syncs across your Apple devices. It autofills in Safari natively; on a Mac running macOS Sonoma (released September 2023) or later, it also autofills in Chrome (and other Chromium browsers) once you install the free “iCloud Passwords” extension from the Chrome Web Store. Earlier macOS versions support Safari only.
  • Bitwarden: works across every major platform and browser. 2FA code generation is a paid-plan feature; the free plan does not include it.
  • 1Password: works across every major platform and browser, generates 2FA codes. No permanent free tier; a paid subscription is required after a trial.
  • LastPass: the password vault’s built-in 2FA codes are a paid-plan feature, but LastPass also offers a separate, free authenticator app (LastPass Authenticator) that generates codes for any account that supports them, independent of the vault.
  • Chrome’s Google Password Manager: free, but does not generate 2FA codes. You would need a separate authenticator app (such as Google Authenticator) alongside it.

Secure the computer you use

A strong password and 2FA protect your Zanda account online, but that protection only holds up if the computer you use to reach it is secure too. A few habits cover the rest:

Lock your screen within 2 minutes

  • Set your computer to lock automatically after 2 minutes of inactivity or less, so nobody can use it if you step away.
  • This matters most in shared spaces where people outside your team pass through, like a shared office or a reception area.
  • On Windows, requiring sign-in when your PC wakes from sleep isn’t guaranteed by default, so check your sign-in settings and turn it on, then set a short screen-off time to match.
  • On Mac, requiring a password after sleep isn’t on by default either. Check your lock screen settings and set it to require a password immediately once the screen saver starts or the display turns off.

Keep antivirus software active

  • Windows includes Microsoft Defender Antivirus, which runs by default and stays active unless you install a different antivirus program, in which case Windows automatically hands protection over to that one instead. Check your security settings to confirm something is active.
  • Mac includes XProtect and Gatekeeper, which automatically screen for known malware and block software from unidentified sources. Keeping macOS updated and installing software only from the App Store or trusted developers is Apple’s recommended baseline, and it’s enough for most people. Add dedicated antivirus software only if your organization requires it.

Turn on disk encryption

  • Disk encryption means nobody can read your computer’s contents without your login password, even if the device is lost or stolen.
  • On Windows, device encryption is on by default on some newer Windows 11 computers, but older devices, upgraded installs, and local (non-Microsoft) accounts often don’t have it enabled, so check your settings and turn it on if it’s off. If your computer doesn’t offer device encryption directly, look for BitLocker instead, available on Windows Pro, Enterprise, and Education editions.
  • On Mac, machines with Apple silicon or a T2 security chip encrypt your data by default at the hardware level, but turn on FileVault itself too: it adds a recovery key and full protection for the data tied to your login.

Secure your phone as well as your computer

  • Set your phone or tablet to require a passcode, PIN, or biometric unlock (Face ID, fingerprint, or the Android equivalent) before it can be opened at all. A password manager is only as secure as the device it’s unlocked on.
  • Require Face ID or fingerprint to open your password manager app itself, on top of your device lock. Most password manager apps offer this as a setting, and it’s worth turning on. On Android, the equivalent options are fingerprint unlock and face unlock, depending on what your device supports.

Choose a strong, memorable master password

  • Your password manager’s own master password is the one password it can’t generate or remember for you, since it’s what unlocks the vault itself, so it needs to be both secure and something you will actually remember. Never write it down.
  • A reliable way to build one: combine a few random, unrelated words, swap a few letters for similar-looking numbers or symbols (for example, “a” to ”@” or “e” to “3”), and add a bit of punctuation. The result is long and hard to guess, but memorable because it’s built from words rather than random characters.

If you think a password has been compromised

  1. Reset your password immediately, and log out of all active sessions using the logout button.
  2. Generate the new password with a password manager. Use a password you have never used anywhere else, at least 12 random characters long, more if the service allows it.
  3. In Zanda, check your Log File (Tools > Log File) for any activity you do not recognize. You can filter it by user, date, page, and IP address.
  4. If anything looks unfamiliar, contact us right away.

Related articles

Was this article helpful?