Look under a keyboard or along the bottom edge of a monitor at almost any front desk and you may find a sticky note with a password on it. It is not laziness. Staff are asked to remember logins for the EMR, email, payroll, a pharmacy portal, a state reporting site and a dozen other tools, each with its own rules. Something has to give, and the sticky note wins.
Security guidance has shifted in recent years to reflect reality. Rather than demanding ever more complicated passwords that people cannot remember, organizations are moving to longer passphrases, multi-factor authentication and password managers. Here is how those pieces fit together.
A password written on a note is visible to anyone who walks by, including visitors, vendors and residents' guests. It can be photographed in a moment. It also tends to be a password that gets reused, because people who write things down are the ones struggling to keep track.
Reused passwords are especially dangerous. When a staff member uses the same password for a streaming service and a work email, a breach at the unrelated company can expose your organization. Attackers routinely try leaked passwords against other sites, a technique known as credential stuffing.
A password manager is an application that stores your logins in an encrypted vault protected by one strong master passphrase, usually together with multi-factor authentication. It can:
Generate long, random, unique passwords for every account
Fill them in automatically so no one has to type or remember them
Warn about reused or known-compromised passwords
Share credentials securely for accounts that truly must be shared
Give administrators visibility and control, in business versions
Because it fills in credentials only on the correct website, it also helps people avoid phishing pages that imitate real ones.
Consumer password managers can work for individuals, but organizations benefit from a business edition with centralized administration. Look for:
Admin controls to onboard and offboard users
Enforced multi-factor authentication
Audit logs
Secure sharing with permission controls
Account recovery that does not weaken security
Support for the devices your staff actually use
Check the vendor's security documentation, and if the tool will store anything related to PHI, confirm whether a business associate agreement is appropriate.
A few passwords will always have to live in someone's head: the computer login, the password manager master passphrase, and perhaps the email account. For these, a passphrase works better than a short complex password. Four or five unrelated words strung together are easier to remember and harder to guess than a short mix of symbols. Current NIST guidance on digital identity favors length and screening against known-compromised passwords over forced complexity rules and frequent mandatory changes.
Some systems are used by many people on shared computers. A password manager is less convenient here. Better options include single sign-on, badge tap, or hardware keys, combined with individual accounts and automatic screen locking. The goal is for every action to be tied to a person, which HIPAA expects through unique user identification.
Start small. Pilot with administrators and the business office, who often manage the most sensitive logins.
Import existing passwords where possible, then replace weak or duplicate ones over time.
Train briefly. A short demonstration of saving and filling a login covers most needs.
Provide a plan for the sticky-note crowd. Offer help moving existing passwords into the vault, and then ask staff to shred the notes.
Set an expectation that sharing passwords by email or text stops.
What if the vault gets hacked? Vaults are encrypted so that the provider does not hold your master passphrase. Using a strong passphrase and multi-factor authentication makes theft of the contents extremely difficult compared with the everyday risks of reuse and notes.
What if someone forgets the master passphrase? Business tools provide recovery options. Set them up before they are needed.
What about personal accounts? Many staff will use the tool for personal logins too, which tends to improve habits across the board.
A password manager is not a substitute for MFA. Use both. If a password is stolen, a second factor can still stop the attack.
UnityCare IT helps healthcare organizations select, deploy and train staff on password management and multi-factor authentication. If your front desk is still running on sticky notes, we can help you replace them with something both safer and more convenient.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172