Seven Password Habits That Quietly Put Resident Data at Risk

Passwords are not glamorous, but they remain a common weak point in healthcare environments. Long-term care facilities are especially exposed because many people share workstations, turnover can be high and some systems are older. Below are seven habits that tend to show up in real facilities, along with practical fixes that do not require turning staff into security experts.

1. Sharing logins at the nurses' station

When three people use one generic login to save time, you lose the ability to say who viewed or changed a record. The HIPAA Security Rule expects unique user identification and audit controls. Shared accounts undermine both.

Fix: Give every person their own account, and make sign-in fast with badge tap, single sign-on or short session handoffs so there is no temptation to share.

2. Passwords written on sticky notes

This is an understandable response to too many systems and strict rules. A note under a keyboard is visible to every visitor and contractor who passes through.

Fix: Provide a password manager approved by the facility, and reduce the number of separate logins through single sign-on where possible. If a written note is unavoidable for a legacy system, a locked drawer is better than a monitor edge.

3. Reusing the same password everywhere

When a staff member uses the same password for a streaming service and the EMR, a breach at the unrelated site hands attackers a working credential. Criminals routinely try leaked credentials against business logins, a technique known as credential stuffing.

Fix: Ask staff to use a unique password for every work system, supported by a password manager. Consider monitoring services that alert you when work email addresses show up in known breach data.

4. Short passwords with predictable tweaks

Passwords like Spring2025! meet old complexity rules but are guessed quickly. Seasonal changes and appended numbers are the first patterns attackers try.

Fix: Favor length over complexity. Current NIST guidance on digital identity emphasizes longer passphrases and discourages forced periodic changes without evidence of compromise. A four-word phrase that only the user would think of is easier to remember and harder to guess.

5. Never changing the default or vendor password

Printers, network switches, cameras, nurse call interfaces and medical devices sometimes ship with default credentials that are published online. They are easy to forget after installation.

Fix: Keep an inventory of devices and confirm that each one has a unique, strong administrative password stored in your password manager. Make this a checklist item for every new installation.

6. Sending passwords by email or text

New hire credentials emailed in plain text may sit in a mailbox for years.

Fix: Use a secure sharing feature in your password manager, or deliver the initial password verbally and require the user to change it at first sign-in. Prefer temporary passwords that expire quickly.

7. Skipping the second factor

A strong password helps, but any password can be phished. Without multi-factor authentication, one convincing fake login page can expose an account.

Fix: Enable MFA for email, remote access and cloud applications first. Our companion post on where to turn MFA on first covers a sensible rollout order.

Build a policy people can follow

A password policy that nobody follows is worse than none, because it creates false confidence. Keep yours short enough to fit on one page:

Unique account for every person, no sharing

Passphrases of at least a defined minimum length

Password manager provided and supported

MFA required on email, remote access and key applications

Prompt reset when compromise is suspected

Same-day disabling of accounts when someone leaves

Review it annually and whenever you change major systems. Include it in new hire orientation, with a five-minute demonstration of the password manager rather than just a handout.

Check what you have today

You can learn a lot in an hour. Walk through two units and note how many shared logins, sticky notes and unchanged default passwords you see. Ask your IT team how many accounts lack MFA and how many former employees still have active logins. The answers usually point to the most valuable first fixes.

UnityCare IT helps healthcare organizations assess account practices, deploy password managers and single sign-on, and write policies that fit clinical workflows. If you would like a quick review of your current setup, reach out and we will walk through it with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034