Passwords are the most argued-about subject in office IT. Staff complain about them, administrators write policies about them and attackers steal them in bulk. Many common rules were built on assumptions that no longer hold, and some of them make security worse by pushing people toward bad habits.
Here are six common myths and what current guidance suggests instead.
For years, policies required frequent changes. Modern guidance, including NIST's digital identity guidelines, advises against forcing periodic changes without a reason. When people must change passwords constantly, they make small, predictable variations, such as adding a number to the end.
Reality: Change a password when there is evidence it may be compromised, such as a breach, a phishing incident or a departing employee who knew it. Otherwise, a strong unique password can stay.
A password such as P@ssw0rd1 follows every complexity rule and is still among the first things attackers try. Length matters far more than clever substitutions.
Reality: Encourage long passphrases, such as four or five unrelated words strung together. They are easier to remember and harder to crack than short, symbol-filled strings.
In a clinical area where a sticky note on a monitor is visible to residents, visitors and contractors, writing down a password is a real problem. But absolute bans push people to reuse one memorable password everywhere, which is worse.
Reality: The bigger risk is reuse. Provide a company-approved password manager so staff do not need to memorize dozens of credentials. Where shared workstations exist, consider badge tap or other sign-in methods that reduce typing.
Attackers use automated tools that test stolen username and password pairs against thousands of organizations. They do not choose targets by size. A small facility with weak sign-in controls is easy to find and attractive because it holds valuable records.
Reality: Every organization that handles protected health information is a target. Size affects your resources, not your risk.
Even an excellent password can be stolen through phishing, a keystroke logger or a breach at an unrelated website where the staff member used the same one.
Reality: Pair passwords with multi-factor authentication, particularly for email, remote access and your health record systems. MFA means a stolen password alone does not open the door.
In busy units, a shared login for a workstation or a medication cart seems efficient. It also destroys accountability. If a resident's chart is viewed improperly, you cannot tell who did it, and HIPAA's access control and audit requirements assume individual accountability.
Reality: Use individual accounts everywhere possible. If fast switching is needed, consider tap-and-go badges that sign users in quickly and securely.
Minimum length of at least 12 to 15 characters, with passphrases encouraged
Screening new passwords against lists of known compromised passwords
No forced periodic changes, but mandatory changes after suspected compromise
A password manager available to all staff
Multi-factor authentication on critical systems
A rule against reusing work passwords on personal accounts
Individual accounts and automatic locking of idle workstations
Show staff what a good passphrase looks like, and why reuse is so risky. Explain that attackers buy leaked passwords and try them elsewhere. Short, specific training works better than a long lecture.
Forgotten passwords are the most common helpdesk request. Offer a self-service reset method with identity verification, and make sure the process works on nights and weekends.
UnityCare IT can review your current password and sign-in policy against modern guidance, set up password management and multi-factor authentication, and help you write rules your staff will really follow.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034