How to login to TINA securely

Share this post

Where therapists do their best work.

Logging in to TINA is a simple process that combines account authentication with an additional End-to-End Encryption (E2EE) unlock step.

Your account password verifies your identity. The E2EE PIN unlocks the organization’s encryption key in your browser. These are separate security mechanisms and serve different purposes.

Logging In to TINA

Step 1: Open the TINA Login Page

Visit the official TINA application at app.tina-assistant.com.

Enter your account email address and password, then select Log in.

Keep your account credentials private and never share them with other users.

Step 2: Complete Account Authentication

TINA verifies your email address and password through the secure login process.

If you are logging in from a new device, you may also be asked to complete verification step, depending on your organization’s authentication settings.

If you are logging in your first time you will get prompted to download recovery codes. They are used to reset or update the password. It adds extra protection against brute-forcing. Without it you cannot update your password.

Recovery Codes and E2EE PINs Are Different

TINA use both a recovery codes and an E2EE PIN, but they are not interchangeable.

Recovery Codes

A recovery codes are used for account-related recovery tasks, such as:

  • Verifying your identity during a password recovery process
  • Authorizing a password update

A recovery code does not unlock encrypted patient data and does not make the E2EE session ready.

E2EE PIN

The E2EE PIN is used to unlock the organization’s client-side encryption key. PIN enables end-to-end encryption of patient health data.

It is used after account login when TINA needs to access protected information. The current E2EE setup uses a six-digit numeric PIN.

Step 3: Unlock End-to-End Encryption

If your organization has E2EE enabled and an encryption key has already been configured, TINA displays an E2EE unlock prompt after login.

Enter the organization’s E2EE PIN.

Once the E2EE step is complete, the session is ready to decrypt protected information and perform encrypted writes.

Logging In from a New Computer or Browser

The E2EE key package is associated with the organization. When you sign in from a new device:

  1. Log in with your TINA email and password.
  2. The browser displays the E2EE unlock prompt.
  3. Enter the same organization E2EE PIN.
  4. You can access protected data after the session becomes ready.

First-Time Organization Setup

If E2EE has not yet been configured for your organization, an authorized (admin) user may be asked to set it up.

Depending on the organization’s existing encryption configuration, TINA may provide options to:

  • Create a new six-digit E2EE PIN
  • Import legacy encryption key material
  • Unlock an existing organization encryption setup

The raw PIN and unencrypted data key are not sent to the server.

What If the E2EE PIN Is Incorrect?

If the PIN is incorrect:

  • The E2EE session remains locked.
  • Protected values cannot be decrypted.
  • Sensitive write operations cannot proceed.
  • You can try entering the PIN again.

A security code, account password, or password-reset token cannot substitute for the E2EE PIN.

If you have forgotten the E2EE PIN, contact your organization administrator or TINA support before creating a new encryption configuration. Creating a new encryption key may prevent access to data protected with the previous key.

Accessing the Dashboard

After successful account login and, when required, E2EE unlock, TINA redirects you to the dashboard.

Your available features depend on:

  • Your user role
  • Your organization’s settings
  • Your subscription plan
  • Whether the E2EE session is unlocked

Some non-sensitive information may remain available while E2EE is locked, but encrypted patient information and sensitive write operations require an active E2EE session.

Tips for a Secure Login

  • Keep your TINA email address and account password private.
  • Keep your E2EE PIN separate from your account password.
  • Do not share your E2EE PIN through insecure communication channels.
  • Do not store the PIN in an unencrypted document or browser note.
  • Never share a recovery code unless you are completing the authorized security flow that requested it.
  • Use only the official TINA login address.
  • Log out when using a shared or public computer.
  • Contact your organization administrator or TINA support if you suspect that your password, security code, or E2EE PIN has been exposed.

Troubleshooting

I Can Log In but Cannot View Protected Data

Your account authentication may have succeeded while the E2EE session remains locked. Enter the correct organization E2EE PIN when prompted.

I Received a Recovery Codes

A recovery codes is normally related to account verification or password recovery. It does not unlock E2EE-protected data. Follow the instructions in the security flow that requested the code.

The E2EE Prompt Appears on Every New Device

This is expected. The encryption key is unlocked in the browser for the active session. Enter the organization’s E2EE PIN on each new device or browser.

I Cannot Remember the E2EE PIN

Do not create a new encryption key without first checking whether the existing organization data can be recovered. Contact your organization administrator or TINA support for assistance.

Summary

TINA uses multiple security layers during login:

  1. Email and password authenticate your account.
  2. Recovery codes support account verification and recovery flows.
  3. The E2EE PIN unlocks the organization’s encryption key locally.
  4. The dashboard becomes available after the required authentication and encryption steps are complete.

Recovery codes and E2EE PINs have different purposes. A recovery code can help verify or recover an account, while only the correct E2EE PIN can unlock the encryption key needed to access protected patient information.

Related posts

[read_time]

Invoicing is a crucial aspect of managing a therapy practice, as it not only ensures that you are compensated for ...

[read_time]

The TINA app is designed to streamline the management of your therapy practice, from client intake to invoicing. Here’s a ...

[read_time]

Logging in to TINA is a simple process that combines account authentication with an additional End-to-End Encryption (E2EE) unlock step. ...

[read_time]

At TINA, protecting the privacy of patient health data is a core priority. TINA’s End-to-End Encryption (E2EE) feature is designed ...

[read_time]

Transcribing audio notes in TINA offers several benefits that can significantly improve your workflow and client management. Transcribing audio therapy ...

[read_time]

We’re dedicated to improving the therapy experience by introducing SMS reminders that ensure your clients never miss a session again. ...

Privacy Policy

In accordance with the GDPR, we inform you that we have adapted our communications to comply with the regulations on the protection of personal data. Your personal data will only be processed for the purposes with which you expressly consent. Consent to the transfer of personal data is voluntary and you can also withdraw your consent at any time in the same way as you gave it. If you do not provide personal data or withdraw your consent, Centrum cognitio d.o.o. will not be able to fulfil the purpose for which the data was collected. In addition, you have the right to access the data, the right to rectification, the right to erasure (“right to be forgotten”), the right to restriction of processing, the right to contract and the right to data portability. To exercise the aforementioned rights or in the event of a complaint, please contact the Personal Data Protection Officer, otherwise contact the address for: Data Protection Officer, Centrum cognitio d.o.o., Šarhova ulica 34, 2000, Slovenia or on e-mail: [email protected].

If you believe that the processing of personal data violates provisions on the protection of personal data, you have the right to lodge a complaint with the Information Commissioner.

The data will be kept until your withdrawal or for as long as necessary to achieve the purpose for which the data was collected.

The controller, the company Centrum cognitio d.o.o., undertakes to process and protect the data in accordance with the Personal Data Protection Act and the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council.

We use the MailChimp marketing platform for the purposes of electronic notification. By registering or filling out the form, you agree that we manage your data under the above conditions and that the information you provide us is simultaneously transmitted to MailChimp, which provides us with this service. The company Centrum cognitio d.o.o. will ensure that MailChimp provides the same level of protection of personal data as required by local and European legislation, in particular by signing EU standard contractual clauses, unless otherwise specified in individual cases.

Cookie policy

Cookie policy

The Electronic Communications Act (Official Gazette No. 109/2012), ZEKom-1, has incorporated rules on the use of cookies and similar technologies to shop or access information stored on users’ computers, tablets or mobile devices into the legal system.

Our website may place a so-called “cookie” on your computer’s browser.

What are cookies?

Cookies are small text files that give us information about how often a person visits our website and what content the user views. Cookies are not harmful and are always temporary. The cookies themselves do not contain any data that would allow a person to be identified. You always have the option to accept or reject cookies. Most web browsers accept cookies automatically, which you can change in the settings so that your computer rejects cookies or you receive a warning before a cookie is stored.

Strictly necessary cookies

These are cookies that are necessary for the proper functioning of the website and without which the transmission of the message on the communication network would not be possible. These cookies enable user-friendly online services, a better user experience and do not require consent.

 Google Analytics

Our website uses Google Analytics, a web analytics service provided by Google. Google Analytics uses cookies to analyse how users use the website. The information obtained by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google [on servers in the United States]. Google will use this data for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this data to third parties where required to do so by law, or where such third parties process the data on Google’s behalf. Google will not associate your IP address with any other data held by Google.

Google Analytics sets the following cookies:

  • _ga 2 years This randomly generated number is used to determine unique visitors to our website.
  • _gid 24 hours This randomly generated number is used to determine unique visitors to our website.
  • _gat 1 minute Limiting the frequency of requests.

You can find detailed information about Google Analytics and your privacy (including how you can control the data sent to Google) at https://policies.google.com/privacy/partners.

Service cookies

We cannot manage the use of third-party cookies; for more information about these cookies, visit the websites of these persons, e.g. Facebook, Twitter, Instagram, YouTube.

If you do not want to use online cookies, you can refuse or disable the storage of cookies in your browser settings. If you agree to the use of our cookies, but not to the use of third-party cookies, you can select the “block third-party cookies” option (reject third-party cookies) – the option may vary slightly between different browsers.

How to manage cookies?

You can also control and change cookie settings in your web browser. For information about cookie settings, select the web browser you are using.

If you have previously given your consent for cookies and later changed your mind and excluded the receipt of cookies in your browser, your visit to the website will be understood as a first visit. In this case, you will receive a cookie notification again.

Additional questions

All further questions about cookies can be sent to us at the email address [email protected]