Managing System Security

Staff Manager has advanced security measures in place to protect user and patient data. You can configure Staff Manager security to the level required for your organization.

In organizations using single sign-on for security, Staff Manager user accounts are tied to their corresponding network accounts and all Staff Manager login dialog boxes are bypassed. Changing user passwords in Staff Manager has no effect on users' network accounts.

Configurable Security Features

These security features are spread throughout the three main Staff Manager applications: Staff Manager Administrator, Staff Manager Client, and Clairvia Web.

Security in Staff Manager Administrator, Staff Manager Client, and Clairvia Web

Administrators use Staff Manager Administrator to:

Administrators use Staff Manager Client to:

Administrators use Clairvia Web to:

Configuring Password Security

Only Enterprise Admin users can configure password security. Complete the following steps to set the level of password security for all Staff Manager users.

  1. From the Configure menu, select App Settings > Password Management. This opens the Password Management page.
  2. Enter a value for the Password must be at least X characters long option. The more characters a password has, the more secure it is. Suggested values are from 6 to 10 characters; the maximum length is 32 characters. Entering a value of zero (0) turns this feature off.
  3. Select at least two of the three options under Password must be a combination of (select at least two).
  4. It is recommended that you select Password cannot contain user login name, first name, or last name. This makes passwords more secure by preventing users from creating passwords containing their first, last, or login names.
  5. Enter a value for the Expires in X days option. Changing passwords on a regular basis increases security. Suggested values are from 30 to 180 days. Entering a value of zero (0) turns this feature off.
  6. Enter a value for the Expire warning within X days option. Entering a value in this option alerts users when their password is going to expire. Suggested values are from 3 to 10 days. Entering a value of zero (0) turns this feature off.
  7. Enter a value for the User is locked out after X failed attempts option. Entering a value in this option makes the application more secure by preventing unlimited login attempts by unauthorized personnel. Suggested values are from 3 to 5 attempts. Entering a value of zero (0) turns this feature off.
  8. Enter a value for the User is locked out after X days of inactivity option. Entering a value in this option makes the application more secure by preventing unlimited access over time. Suggested values depend on how often users expect employees to log into the application; some facilities might lock users out after 7 days of inactivity, while other facilities might lock users out after 30 days of inactivity. Entering a value of zero (0) turns this feature off.
  9. If you want, you can select Enable user security questions. This lets users answer security questions to give them access to the application if they forget their passwords.
  10. Click Save Changes to save your changes or Reset to restore the original settings.

Using the Account Maintenance Page

Depending on the way your organization configured security, users can be locked out of the application due to multiple failed password entries or lack of activity. Administrators can use the Account Management page to unlock user accounts; they can also review detailed information about the locked out user account.

Unlocking User Accounts

  1. From the Tools menu, select Account Maintenance. This opens the Account Maintenance page.
  2. Select the box beside the user account or accounts to be unlocked.
  3. Click Unlock User Account.
  4. Click OK to confirm unlocking the selected account or accounts.

Unlocking a user's account also clears their current password. The user has to create a new password the next time they log in.

Reviewing Information on the Account Maintenance Page

The Account Maintenance page provides administrators with the following information concerning locked user accounts.

You can sort account information in any column by clicking on the column title. Clicking once sorts the information in ascending order; clicking again sorts it in descending order.

