Password Myths That Quietly Put Resident Records at Risk

Passwords are the oldest security control in healthcare IT, and the one surrounded by the most folklore. Staff have been told to change passwords constantly, add symbols and never write anything down. Some of that advice made sense decades ago. Some was never helpful. Current guidance from organizations such as NIST has shifted, and care facilities can make their lives easier and more secure by adjusting.

Here are seven myths worth retiring.

Myth 1: Complex Beats Long

Reality: Length matters more than odd characters. A passphrase of several unrelated words is generally harder to guess and easier to remember than a short password full of substitutions like "P@ssw0rd!". NIST guidance emphasizes length and discourages forced composition rules.

Myth 2: Change Passwords Every 60 Days

Reality: Forced frequent changes lead people to make small, predictable edits, such as adding a number at the end. Current NIST guidance recommends changing passwords when there is evidence of compromise rather than on a fixed schedule. Check with your compliance and insurance requirements, but do not assume constant rotation is the safest option.

Myth 3: Writing a Password Down Is Always a Disaster

Reality: A password in a locked drawer at home is less risky than a reused password in someone's head. The real danger is a sticky note on a monitor at a nurses' station. The best answer is a password manager for staff who need many credentials, and single sign-on or badge tap where possible.

Myth 4: Nobody Would Target a Small Facility

Reality: Attackers use automated tools that test stolen credentials against many organizations. Size does not matter to a bot. If a staff member's password was exposed in an unrelated breach and reused at work, it can be tried against your email.

Myth 5: Shared Logins Are Fine on a Busy Unit

Reality: Shared accounts remove accountability. HIPAA requires unique user identification so access to protected health information can be traced to a person. If a shared login is a workaround for slow logins, fix the real issue with faster authentication methods, such as badge tap, rather than accepting the risk.

Myth 6: A Strong Password Makes MFA Unnecessary

Reality: Strong passwords can still be phished, stolen by malware or leaked from another service. Multi-factor authentication protects the account even when the password is known.

Myth 7: IT Needs to Know Your Password

Reality: A legitimate technician can reset your password without knowing your current one. Staff should never read a password aloud, text it or email it. If someone asks, treat it as a warning sign.

What to Do Instead

Set a sensible policy

Require a minimum length, such as 12 to 16 characters for staff accounts, and encourage passphrases.

Block commonly used and previously exposed passwords.

Do not force routine changes without reason; require a change after suspected compromise.

Turn on lockout or throttling after repeated failed attempts.

Give people tools

A password manager approved by the organization

Multi-factor authentication on email, remote access and key systems

A simple, quick way to reset a password after hours

Train briefly and often

Cover why reuse is dangerous: one breached service can open many doors. Encourage staff to use different passwords for work and personal accounts.

Audit regularly

Disable accounts of departed staff immediately

Review administrator accounts quarterly

Remove old shared accounts

Check for default passwords on devices like printers, cameras and network equipment

Aligning With HIPAA

The Security Rule requires procedures for creating, changing and safeguarding passwords as part of your administrative and technical safeguards, but it does not dictate specific formulas. Document your reasoning and be consistent.

How UnityCare IT Can Help

UnityCare IT helps care organizations modernize password and access policies, deploy password managers and multi-factor authentication, and clean up old accounts. If your current policy has not been reviewed in years, we are happy to take a look.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172