The page says SMS OTP delivery is failing. On-call opens the alert and sees a rise in codes that users requested but never verified, while a patient is waiting to complete login and receive a generated clinical report by email. Polling delivery status without webhooks looks like the direct response, but polling every message until a terminal state is the wrong default. TL;DR: a pull-only SMS service can support login 2FA, but delivery polling should be bounded operational evidence, not the cl...