Password Managers vs Sticky Notes: Settling the Debate

Look under a keyboard or along the bottom edge of a monitor at almost any front desk and you may find a sticky note with a password on it. It is not laziness. Staff are asked to remember logins for the EMR, email, payroll, a pharmacy portal, a state reporting site and a dozen other tools, each with its own rules. Something has to give, and the sticky note wins.

Security guidance has shifted in recent years to reflect reality. Rather than demanding ever more complicated passwords that people cannot remember, organizations are moving to longer passphrases, multi-factor authentication and password managers. Here is how those pieces fit together.

Why sticky notes are a real risk

A password written on a note is visible to anyone who walks by, including visitors, vendors and residents' guests. It can be photographed in a moment. It also tends to be a password that gets reused, because people who write things down are the ones struggling to keep track.

Reused passwords are especially dangerous. When a staff member uses the same password for a streaming service and a work email, a breach at the unrelated company can expose your organization. Attackers routinely try leaked passwords against other sites, a technique known as credential stuffing.

What a password manager does

A password manager is an application that stores your logins in an encrypted vault protected by one strong master passphrase, usually together with multi-factor authentication. It can:

Generate long, random, unique passwords for every account

Fill them in automatically so no one has to type or remember them

Warn about reused or known-compromised passwords

Share credentials securely for accounts that truly must be shared

Give administrators visibility and control, in business versions

Because it fills in credentials only on the correct website, it also helps people avoid phishing pages that imitate real ones.

Choose a business-grade tool

Consumer password managers can work for individuals, but organizations benefit from a business edition with centralized administration. Look for:

Admin controls to onboard and offboard users

Enforced multi-factor authentication

Audit logs

Secure sharing with permission controls

Account recovery that does not weaken security

Support for the devices your staff actually use

Check the vendor's security documentation, and if the tool will store anything related to PHI, confirm whether a business associate agreement is appropriate.

Passphrases for the passwords people must remember

A few passwords will always have to live in someone's head: the computer login, the password manager master passphrase, and perhaps the email account. For these, a passphrase works better than a short complex password. Four or five unrelated words strung together are easier to remember and harder to guess than a short mix of symbols. Current NIST guidance on digital identity favors length and screening against known-compromised passwords over forced complexity rules and frequent mandatory changes.

Special case: shared and shift workstations

Some systems are used by many people on shared computers. A password manager is less convenient here. Better options include single sign-on, badge tap, or hardware keys, combined with individual accounts and automatic screen locking. The goal is for every action to be tied to a person, which HIPAA expects through unique user identification.

Rolling out a password manager

Start small. Pilot with administrators and the business office, who often manage the most sensitive logins.

Import existing passwords where possible, then replace weak or duplicate ones over time.

Train briefly. A short demonstration of saving and filling a login covers most needs.

Provide a plan for the sticky-note crowd. Offer help moving existing passwords into the vault, and then ask staff to shred the notes.

Set an expectation that sharing passwords by email or text stops.

Address common objections

What if the vault gets hacked? Vaults are encrypted so that the provider does not hold your master passphrase. Using a strong passphrase and multi-factor authentication makes theft of the contents extremely difficult compared with the everyday risks of reuse and notes.

What if someone forgets the master passphrase? Business tools provide recovery options. Set them up before they are needed.

What about personal accounts? Many staff will use the tool for personal logins too, which tends to improve habits across the board.

Combine with multi-factor authentication

A password manager is not a substitute for MFA. Use both. If a password is stolen, a second factor can still stop the attack.

Practical next step

UnityCare IT helps healthcare organizations select, deploy and train staff on password management and multi-factor authentication. If your front desk is still running on sticky notes, we can help you replace them with something both safer and more convenient.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172