Skip to main content

Security Settings at a Glance

A quick guide to the security settings administrators see in CoolFocus.

Written by Jonathan Marbutt

The Security settings area brings your access tools together. Use this page as a quick map, then open the full article for step-by-step detail.


Users

People who can sign in to CoolFocus for your organization. Review access, assign a user group, turn Administrator on or off, and link each login to a People record when they use schedule or Home views.

See Users.


Invitations

Pending invites for people who still need to create their login.


User Groups

Groups of users who share the same access — which areas they can open, whether they can view, add, edit, or delete, and whether they are a module admin who can manage a module's settings.


IP Addresses

Approved network locations for sign-ins when your organization uses IP restrictions (for example, office-only access).


Multi-factor authentication

Whether staff must confirm a second factor — an authenticator app, a text message code, or a backup code — before they can enter your organization. Any staff member can turn MFA on for their own login, and an administrator can require it for everyone.


Security Log

A record of security-related events — successful sign-ins, failed sign-ins, logouts, and denied IP addresses. Filter by event type and date. From a recent IP denied row you can Approve IP for a short window.


User Logs

A unified timeline of staff sign-in activity, clinical record access, and summarized record changes. Filter by date, category, or a specific user. You can also open a person's log from Users → Quick Actions → View activity log.


For a compliance-focused view of chart access specifically, use the Chart Access Log report instead of User Logs. It lists every time a clinical chart's detail or a physician review sheet was opened, with the accessing user, the record, and the timestamp. It lives in Reporting, not in Security settings, and is restricted to administrators.

See Reports by CoolFocus Module for the Compliance section.


Data Access Rules

When your plan includes them, data access rules limit which individual records a user group can see or change (for example, only one campus's donors). They sit on top of user groups.


Legal & Compliance

Review and sign your organization's Business Associate / Vendor Confidentiality Agreement (BAA), download the executed PDF once signed, and find related compliance documents.


Before you change security

Write down the change you are making and why. If something does not work as expected, this makes it easier to undo or adjust.


Related

Did this answer your question?