Password Habits That Fail in Healthcare and Better Replacements

Passwords are the oldest security control still in daily use, and in healthcare they are often managed in ways that make attackers' lives easier. Staff are rushed, computers are shared and rules were written years ago. The result is familiar: passwords on sticky notes, one login used by a whole shift and complex rules that push people toward predictable patterns.

Here are habits that fail, and better approaches grounded in current guidance such as NIST's digital identity recommendations.

Habit 1: Shared logins

A shared account for a unit or a med cart is convenient, but it destroys accountability. If a resident record is viewed or changed inappropriately, you cannot tell who did it. HIPAA requires unique user identification and audit controls so activity can be traced to an individual.

Better approach: give every person their own account, and make signing in fast with badge tap, proximity cards or single sign-on so that nobody is tempted to share.

Habit 2: Passwords on sticky notes

Passwords taped to monitors are visible to visitors, vendors and anyone walking through. Staff do this because they have too many passwords or the rules are impractical, not because they are careless.

Better approach: reduce the number of passwords through single sign-on, provide an approved password manager and make it easy to reset a forgotten password through a verified process.

Habit 3: Short, complex passwords changed constantly

Rules such as eight characters with symbols, changed every 30 days, tend to produce passwords like Spring2024! followed by Summer2024!. Attackers know these patterns. NIST guidance moved away from mandatory periodic changes and arbitrary complexity rules.

Better approach:

Favor length. A passphrase of several unrelated words is easier to remember and harder to guess.

Require a change when there is evidence of compromise, not on an arbitrary schedule.

Check new passwords against lists of commonly used or previously breached passwords.

Habit 4: Reusing passwords

When someone uses the same password for work email and a personal shopping site, a breach at the shopping site exposes the work account. Attackers routinely try stolen credentials against other services.

Better approach: ask staff never to reuse their work password anywhere else. Provide a password manager so unique passwords are practical.

Habit 5: Passwords without a second factor

Even good passwords can be stolen through phishing. A password is a single point of failure.

Better approach: enable multifactor authentication on email, remote access and administrator accounts first, then expand to other systems that hold resident or financial data.

Habit 6: Default and vendor passwords left in place

Printers, cameras, firewalls and wireless controllers often ship with well-known default passwords. These are among the first things attackers try.

Better approach: change every default credential at installation, store the new ones in a secured vault and add this to your device setup checklist.

Habit 7: Admin accounts used for everyday work

If someone with administrator rights checks email and clicks a malicious link, the attacker inherits those powerful privileges.

Better approach: give administrators separate accounts for daily tasks and for administration, and protect the latter with stronger controls.

Habit 8: Slow or complicated resets

When a reset takes hours, staff look for shortcuts. Conversely, resets that are too easy let social engineers take over accounts.

Better approach: use a defined process that is quick but verified, such as calling back a known number or confirming through a supervisor, and self-service resets with multifactor verification where possible.

Practical policy points

A short, realistic password policy for a care facility might say:

Every person has a unique account.

Passphrases of at least 14 characters are encouraged, and a password manager is provided.

Passwords are never shared, written down in public view or reused outside of work.

Multifactor authentication is required for email and remote access.

Any suspected compromise is reported to IT immediately.

Adjust the length and details to your systems and risk analysis, and make sure your supervisors model the behavior.

Getting help

UnityCare IT helps healthcare organizations modernize password and access policies, deploy password managers and single sign-on, and train staff in practical habits. If your current rules are creating more workarounds than protection, we can help you update them.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172