Sign-in & security
BirthTracks protects the records you hold, so signing in is built to be both easy day-to-day and hard for anyone else to get through. This page covers every way you can sign in and the security controls on your account.
Signing in with email and password
Section titled “Signing in with email and password”The standard path is your email address and password on the Log in to your account page. If you’ve forgotten your password, choose Forgot your password? on that page and we’ll email you a reset link.
Continue with Google
Section titled “Continue with Google”Where Google sign-in is enabled for your environment, a Continue with Google button appears above the email-and-password form on the log-in and sign-up pages. It’s an alternative to a password, not a replacement for your account — the same account works either way.
You manage the Google link from Settings → Profile, under Connected accounts:
- If Google isn’t linked, choose Connect to link it.
- If it’s linked, the row shows Connected, and you can choose Disconnect.
Passkeys
Section titled “Passkeys”A passkey lets you sign in with your device instead of a password — Face ID, Touch ID, Windows Hello, or a hardware security key. A passkey stays on your device and only works on this site, so it can’t be phished or replayed.
Passkeys are currently in beta and available to participating practices. Where they’re available, you manage them on the Passkeys page in Settings:
- Add passkey — give it a name (for example, “MacBook Touch ID”) and follow your device’s prompt.
- Each passkey shows the device it lives on and when it was last used.
- Remove a passkey you no longer use; you’ll no longer be able to sign in with it.
Two-factor authentication keeps working alongside a passkey.
Two-factor authentication
Section titled “Two-factor authentication”Two-factor authentication (2FA) adds a one-time code from an authenticator app on top of your password. It’s available to every account — whether it’s required depends on your practice’s policy for your role, and it isn’t required by default.
Set it up from the Two-factor authentication page in Settings:
- Choose Enable.
- Scan the QR code with your authenticator app, or enter the Setup key by hand.
- Enter the generated Code and choose Confirm.
Once enabled, store the recovery codes we show you somewhere safe — they let you back in if you lose your authenticator device. You can Show recovery codes, Regenerate recovery codes, or Disable 2FA from the same page.
When your role requires a second factor, you’ll be sent to this page to set one up before you can continue. On participating practices a registered passkey satisfies that requirement too, so you can choose Set up a passkey instead.
After you sign in with your password, you’ll be asked for your authenticator code on the two-factor challenge screen before you reach the app.
Automatic sign-out when idle
Section titled “Automatic sign-out when idle”For safety on shared and unattended computers, BirthTracks signs you out after 15 minutes of inactivity. Sign back in to pick up where you left off. This is separate from staying signed in on a device you trust.