Well, there are a couple things you could do, depending on exactly how you want to handle it.
You could limit people logging on by IP address range. I don't like this idea, because it limits where people can log in from.
Have a table called 'loggedin'. Place a row in there with a timestamp when a user logs in and whenever they do certain functions have it update this time stamp. Now, when they go to log in, check this table for a login under that username with activity in the last 10-15 minutes, or whatever your limit is. If there is a login with activity in the last 15 minutes, don't allow a login.
Hope that helps,
Matt Wade
codewalkers.com