Walk through almost any care facility and you will find at least one password on a sticky note. It is rarely carelessness. Staff juggle dozens of logins, forced password changes, and strict time pressure, so they do the human thing and write it down.
Password managers address the root cause, but they come with plenty of misconceptions. Here is what is true and what is not.
Reality: Reputable password managers encrypt the vault so that the provider cannot read its contents, and access requires a master password plus, ideally, multi-factor authentication. Compare that to the alternative: reused passwords across many sites, where one breach elsewhere can unlock several accounts. No tool is risk-free, but for most staff a password manager significantly reduces risk compared with reuse and sticky notes.
Reality: That is exactly the problem a manager solves. Staff only need to remember one strong passphrase, and the tool creates and fills the rest. Guidance from NIST has moved away from forcing frequent, complex password changes and toward longer passphrases, screening against known-breached passwords, and changing credentials when there is evidence of compromise.
Reality: It depends on how they are deployed. Business-grade tools allow each employee to have their own vault, accessed from a shared workstation after signing in as themselves. Be careful with:
Browser autofill saved on a shared Windows profile, which can expose one person's credentials to the next user
Staff leaving vaults unlocked when they walk away
Shared logins for clinical systems, which defeat individual accountability
To reduce risk, use individual logins, auto-lock timers, and single sign-on where your systems support it. For some clinical applications, badge-tap logins or single sign-on may be a better fit than a vault.
Reality: Some clinical applications limit or discourage automated fill. Ask your vendor what they support. Many staff logins can still be managed by a tool even if a particular application requires typed entry. The best approach is usually layered: single sign-on for what it supports, a vault for everything else, and MFA across the top.
Reality: Free personal products help individuals, but they usually lack what organizations need: central administration, the ability to recover access when someone leaves, shared vaults for departmental accounts, reporting, and policy enforcement. Mixing personal vaults with work credentials also creates a problem when an employee departs and the facility has no way to retrieve logins for shared systems.
Reality: Adoption rises when the tool makes work easier. Staff who no longer have to remember or reset passwords generally appreciate that. Success depends on rollout:
Explain the why in plain language
Provide short hands-on sessions at shift change
Offer a one-page quick start
Make sure the helpdesk can handle forgotten master password questions according to a clear recovery process
A business-class password manager with admin controls and audit logs.
Multi-factor authentication on the vault itself.
Individual vaults for every employee and shared folders for departmental or vendor accounts, with access limited by role.
A written policy covering which accounts go in the manager, who can share what, and what happens at offboarding.
Break-glass access for administrators in emergencies, stored securely and documented.
Regular review of shared items and former employees' access.
A password manager does not replace other controls. Keep multi-factor authentication on email and remote access, patch software, and train staff on phishing. A strong password cannot protect an employee who enters it on a convincing fake login page, though many password managers help here by refusing to fill credentials on sites that do not match.
Pilot with a small group, such as administrative staff or one unit, collect feedback, then expand. Start with the accounts that matter most, such as email, banking and cloud services, before moving into everything else.
UnityCare IT can help select, deploy and support a password manager that fits your staffing and workstation reality, including training for shift workers. If sticky notes are still part of your security program, it may be time to talk.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172