One-Time Password Protection
Services
Accessibility (WCAG 2.1)
UI & Visual Design
role
UX/UI Designer
Platform
Web ~ Desktop
Timeline
6 weeks • 2023
Project Info
As cyber attacks grew more frequent and complex, MedeAnalytics needed to add an extra layer of security to its login flow. The requirement was driven by both user safety and insurance compliance, with the goal of introducing a one-time password step without disrupting an experience users were already familiar with. I led the design over six weeks, starting with comparative research into OTP flows across existing products to understand common patterns and where they differed. That research directly shaped updates to the acceptance criteria, including partially masking the email on file and building in a device memory option. From there I worked through the flow in stages, tackling step count, brand guideline application, button logic, error states, and sizing adjustments to the existing login screen. The final design introduces a single additional step into the existing flow, keeping disruption minimal while meaningfully improving account security. Help options and error handling were designed with future self-service iterations in mind, so the foundation is there to build on when the next version comes around.
The process & execution 🤺
01 Research & emphasize
The majority of my research heavily relied on searching around and interacting with designs out in the wild. Many of the flows already in place throughout products followed a similar flow, but there were some differences in what they had implemented and the requirements put in place for the V1 of our security.

02 Define & ideate stage
Given the time and resources for this project, conducting a comparative analysis provided me with the proper insight and knowledge to begin strategizing solutions to the problem and work with PMs to update acceptance criteria.


03 Starting the design

Key takeaways
What initially seemed like a straightforward ticket became something so much more. That said, it was crucial to my design process to break this down into tinier, more digestible steps. I found it helpful to check in with my team and other departments that were involved early and often to ensure that the logic we were putting forward was feasible. Of course, during the sprint, there were minor setbacks, but nothing as drastic as if I hadn't been communicating with the other teams throughout. All in all, there are always next steps, such as including a way for users to do more than contact support when they get stuck, but as far as a version one goes, this flow covers the initial bases.



