For years, staff were told to create passwords with a capital letter, a number and a symbol, then change them every ninety days. The result was predictable: Summer2025!, followed by Fall2025!, followed by a sticky note under the keyboard. Security guidance has moved on, and it is worth updating your habits to match.
This post summarizes current thinking in practical terms for care teams, including the thorny issue of logins shared at busy nurse stations.
NIST's digital identity guidelines, which many organizations follow, recommend favoring longer passwords and screening them against lists of known compromised passwords. They also advise against forcing regular password changes unless there is evidence of compromise, and against rigid composition rules that push people toward predictable patterns.
The takeaway is simple: length and uniqueness matter more than complexity tricks.
A passphrase is a string of several unrelated words, easier to remember and harder to guess than a short complex password. Encourage staff to:
Use at least a dozen or more characters, with longer being better.
Combine random words rather than a famous quote or a personal detail.
Avoid names of residents, pets, sports teams or the facility.
Never reuse a work password anywhere else.
A short training session with a live example makes this stick.
When a website unrelated to work suffers a breach, attackers try the stolen email and password on other services. If an employee reuses a password, a leak from a shopping site can open the door to work email. Unique passwords for every account contain the damage.
Nobody can remember dozens of unique passphrases. A password manager stores them securely and fills them in. For organizations, a business-grade manager offers:
Shared vaults for credentials that must be shared, with access tracked and revocable.
Administrative control over who has access.
Policy settings and breach alerts.
Secure sharing instead of passing credentials by email or text.
Protect the manager itself with a strong master passphrase and multi-factor authentication.
Even strong passwords can be phished. Multi-factor authentication limits the harm if one is stolen. Turn it on for email, remote access, the EHR if it supports it and any administrative accounts first.
Some systems can compare new passwords against lists of known breached ones and block them. Ask your IT provider whether your directory or identity platform supports this.
Shared logins are common in care settings because speed matters. A generic login like NURSE1 may seem harmless, but it creates real problems:
You cannot tell who accessed a resident record, which undermines audit controls the HIPAA Security Rule expects.
Departing staff still know the password.
Passwords on shared accounts are rarely changed.
Responsibility is blurred when something goes wrong.
Give each person a unique login and make signing in fast with badge tap or single sign-on.
Use fast user switching on shared computers.
For devices that truly need a shared account, such as a kiosk or a wall display, lock the account down to a narrow function with no access to PHI.
For shared service accounts used by software, store credentials in a vault and rotate them when staff change.
Write passwords on notes near monitors.
Share passwords by text or email.
Save work passwords in personal browsers on shared devices.
Use default passwords on printers, cameras or network equipment. Change them during setup.
Attackers often call the helpdesk pretending to be a staff member. Set a verification process for resets, such as calling back a known number or having a supervisor confirm the request.
Change passwords when there is evidence of compromise, when a staff member who knew a shared secret leaves, or after an incident. Otherwise, avoid arbitrary expiration, which tends to weaken passwords.
Do staff know what a passphrase is?
Does everyone have a unique login?
Is there an approved password manager?
Is MFA turned on for email and remote access?
Are default passwords changed on devices?
UnityCare IT helps healthcare and senior-living organizations adopt password managers, single sign-on and MFA that work on a busy floor. If shared logins are a concern in your building, we can help you find alternatives.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172