Ask staff how they remember passwords and you will hear familiar answers: the same one everywhere, a variation on the resident's room number, a sticky note under the keyboard. None of this is laziness. People are asked to remember many passwords, and a busy hall leaves no time to think about it.
Password managers are one of the most effective fixes, but they come with myths on both sides. Some people think they are unsafe. Others think they solve every problem. Here is what is actually true.
Reality: A reputable password manager stores credentials in an encrypted vault protected by one strong master passphrase and, ideally, a second factor. It is much safer than the common alternative, which is reusing the same few passwords across email, banking and clinical systems. When one of those sites is breached, attackers try the same password everywhere else.
The risk is real if the master password is weak or shared, or if the vault is not protected with multi-factor authentication. That is a setup problem, not a reason to avoid the tool.
Reality: Staff adopt tools that save them time. If a password manager fills in logins automatically and removes the need to remember or type anything, adoption is much higher. If it adds steps on every login, they will find workarounds.
Where possible, combine it with tools made for shared clinical workstations, such as badge tap-in or single sign-on. A password manager is best for web applications, vendor portals and administrative tools, while single sign-on and badge access handle the workstations used all day on the floor.
Reality: Written passwords may be visible to visitors, contractors, residents, family members and former employees. Photos of a screen with a sticky note in view have been an issue in many industries. Under the HIPAA Security Rule, you must have procedures for creating, changing and safeguarding passwords if you use them for access control. Passwords stuck to monitors are hard to defend in a risk analysis.
Reality: They do different jobs. A manager helps create and store unique, strong passwords. MFA adds a second proof of identity. You want both. Together, a stolen password is far less useful to an attacker.
Reality: Current guidance, including from NIST, favors length over forced complexity and discourages frequent mandatory resets unless there is evidence of compromise. A passphrase of several random words is easier to remember and harder to guess than a short string full of symbols. Frequent forced changes often lead people to make small, predictable changes such as adding a number at the end.
Choose a business-grade password manager with an administrator console, shared vaults, audit logs and support for MFA and offboarding.
Start with people who handle the most sensitive accounts: administrators, the business office, HR and IT.
Set up shared vaults for credentials that several people legitimately need, such as vendor portals or social media accounts, so no one emails passwords around.
Require a strong master passphrase and MFA for every user.
Train staff on three skills: creating the master passphrase, using auto-fill, and generating a unique password for each site.
Plan the offboarding process so that access is removed and shared passwords are rotated when someone leaves.
Review the manager's reports for weak, reused or breached passwords and fix those first.
Shared logins are a common practice and a common weakness, because you cannot tell who did what. Where a shared account is unavoidable, such as a legacy device, document it, restrict what it can access, store the password in a shared vault rather than on paper and change it whenever someone with access leaves. Treat each shared login as a risk to be reduced over time.
Never reuse the master passphrase anywhere else
Do not share your vault with anyone, including IT
Lock your workstation when you step away
Report any suspicion that a password has been exposed
UnityCare IT can help you select, deploy and train staff on a password manager and clean up shared accounts across your clinical and business systems. If you are not sure where to begin, we can start with a brief review of how your staff currently handle passwords and what quick wins are available.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172