Passwords are not glamorous, but they remain a common weak point in healthcare environments. Long-term care facilities are especially exposed because many people share workstations, turnover can be high and some systems are older. Below are seven habits that tend to show up in real facilities, along with practical fixes that do not require turning staff into security experts.
When three people use one generic login to save time, you lose the ability to say who viewed or changed a record. The HIPAA Security Rule expects unique user identification and audit controls. Shared accounts undermine both.
Fix: Give every person their own account, and make sign-in fast with badge tap, single sign-on or short session handoffs so there is no temptation to share.
This is an understandable response to too many systems and strict rules. A note under a keyboard is visible to every visitor and contractor who passes through.
Fix: Provide a password manager approved by the facility, and reduce the number of separate logins through single sign-on where possible. If a written note is unavoidable for a legacy system, a locked drawer is better than a monitor edge.
When a staff member uses the same password for a streaming service and the EMR, a breach at the unrelated site hands attackers a working credential. Criminals routinely try leaked credentials against business logins, a technique known as credential stuffing.
Fix: Ask staff to use a unique password for every work system, supported by a password manager. Consider monitoring services that alert you when work email addresses show up in known breach data.
Passwords like Spring2025! meet old complexity rules but are guessed quickly. Seasonal changes and appended numbers are the first patterns attackers try.
Fix: Favor length over complexity. Current NIST guidance on digital identity emphasizes longer passphrases and discourages forced periodic changes without evidence of compromise. A four-word phrase that only the user would think of is easier to remember and harder to guess.
Printers, network switches, cameras, nurse call interfaces and medical devices sometimes ship with default credentials that are published online. They are easy to forget after installation.
Fix: Keep an inventory of devices and confirm that each one has a unique, strong administrative password stored in your password manager. Make this a checklist item for every new installation.
New hire credentials emailed in plain text may sit in a mailbox for years.
Fix: Use a secure sharing feature in your password manager, or deliver the initial password verbally and require the user to change it at first sign-in. Prefer temporary passwords that expire quickly.
A strong password helps, but any password can be phished. Without multi-factor authentication, one convincing fake login page can expose an account.
Fix: Enable MFA for email, remote access and cloud applications first. Our companion post on where to turn MFA on first covers a sensible rollout order.
A password policy that nobody follows is worse than none, because it creates false confidence. Keep yours short enough to fit on one page:
Unique account for every person, no sharing
Passphrases of at least a defined minimum length
Password manager provided and supported
MFA required on email, remote access and key applications
Prompt reset when compromise is suspected
Same-day disabling of accounts when someone leaves
Review it annually and whenever you change major systems. Include it in new hire orientation, with a five-minute demonstration of the password manager rather than just a handout.
You can learn a lot in an hour. Walk through two units and note how many shared logins, sticky notes and unchanged default passwords you see. Ask your IT team how many accounts lack MFA and how many former employees still have active logins. The answers usually point to the most valuable first fixes.
UnityCare IT helps healthcare organizations assess account practices, deploy password managers and single sign-on, and write policies that fit clinical workflows. If you would like a quick review of your current setup, reach out and we will walk through it with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034