Your part in keeping data secure
FCR is built with strong protections (see How FCR protects your data), but the security of client information also depends on how your team uses it day to day. None of this is complicated — it's the same good habits that protect any sensitive system.
Your account and password
- Use a strong, unique password for FCR — not one you reuse on other sites.
- One account per person. Never share a login. Each staff member signs in as themselves so that the activity record stays accurate and access can be managed individually.
- If you think your password may have been exposed, change it (see Logging in & your account).
Protect your authenticator
Two-step verification only protects you if your authenticator stays in your hands.
- Don't share your one-time codes with anyone — no one at FCR or your agency will ever ask for one.
- When you change phones, move your authenticator app to the new device before wiping the old one, so you don't lose access.
On shared or public devices
- Sign out when you finish on a shared or public computer.
- Lock your screen whenever you step away from a device that's signed in.
Keep staff access current
When someone leaves your agency or changes roles, update their access promptly — deactivate departed staff and adjust roles so access always matches who should have it. Stale accounts are one of the most common security gaps, and this is the single most important thing leadership does to keep an agency's data secure.
Handle PHI carefully outside FCR
FCR keeps client information protected inside the system — the risk is usually when information leaves it.
- Keep client details out of support messages and email. When you contact support, describe what went wrong, not whose record it happened on — no names, dates of birth, or case numbers.
- Be careful with screenshots and exported files; store and share them only through approved, secure channels.
If a device that can access FCR is lost or stolen, or you spot anything that looks like a security problem, report it right away to support@myfcr.org and tell your practice manager. Quick reporting lets access be secured before there's any risk to client data.
Frequently asked questions
Will anyone from FCR ever ask for my password or a verification code? No. Never share your password or one-time codes with anyone — a request for them is itself a warning sign.
A coworker is locked out — can they just use my login for now? No. Don't share accounts. A practice manager can reset their access or sort out their two-step verification quickly.
What should I do the moment I realize my phone is missing? Report it to support@myfcr.org and your practice manager. FCR doesn't store client data on the device, but securing your account promptly is still the right move.
Who's responsible for removing people who've left? Practice managers and admins. Keeping the staff roster current is part of the agency's security responsibility.
Need help with something this guide didn't cover? Contact support and we'll walk you through it.