Many organizations still follow password rules written fifteen or twenty years ago: change it every ninety days, include a capital letter, a number and a symbol, never write it down. Staff dutifully comply, and then end up with Summer2025! followed by Fall2025! on a sticky note. Current guidance from standards bodies, including NIST, has moved away from several of these habits because they push people toward predictable patterns.
Here are common myths and what actually works better for a healthcare environment.
Reality: Forced periodic changes tend to produce weak, predictable passwords with a small tweak each time. NIST guidance recommends changing passwords when there is evidence of compromise rather than on a fixed schedule. That does not mean never changing them. It means you should change them promptly if a breach is suspected, if the password appears in a known leaked list, or when an employee leaves.
Reality: Requirements for symbols and mixed case often lead to patterns like Password1!. Length matters more. A passphrase of several unrelated words is easier to remember and harder to guess than a short, complex string. Encourage staff to use four or more random words, and allow spaces.
Reality: The risk depends on where it is. A password hidden under a keyboard in a public hallway is a problem. A password manager, or a locked drawer for rarely used credentials, is a reasonable approach for many people. The better goal is to reduce how many passwords staff must memorize, not to ban every written aid.
Reality: Attackers often use automated tools that try stolen credentials against thousands of organizations. Size does not protect you. Care providers hold sensitive data and depend on continuous operations, which makes them attractive.
Reality: Even a strong password can be stolen through phishing or a data breach at another website. Multi-factor authentication adds a second check so that the password alone does not open the door. It is one of the most effective steps most organizations can take.
Reality: Shared accounts at a nurse station make it impossible to know who accessed a record, which is a problem for audit controls under the HIPAA Security Rule. Faster sign-in options such as badge tap, single sign-on and sensible session lengths help address the real complaint, which is speed.
Set a minimum length of at least 12 to 14 characters, and allow longer passphrases
Block passwords that are common, such as seasons, names or the facility name, or that appear in breach lists
Do not force routine expiration, but require a change after any suspected compromise
Require multi-factor authentication for email, remote access and any system with resident data
Provide a company-approved password manager so staff do not reuse passwords
Ban reuse of work passwords on personal accounts
Give every person a unique account
Policies fail when they ignore the workday. Think about the nurse who logs in many times per shift, the aide who rotates between halls and the receptionist who handles dozens of calls.
Use single sign-on where you can, so one secure login opens several systems
Consider badge or proximity readers for shared workstations
Set automatic screen lock that is short enough to protect data but not so short that it disrupts care
Make password resets quick with self-service, and verify identity carefully when staff call the helpdesk
A short explanation helps. Tell staff that attackers use leaked passwords from other sites, that reuse is the main danger, and that the aim is fewer, stronger passwords plus a second step. People follow rules more willingly when they understand what problem the rules solve.
Pull up your password policy and compare it with the list above. Check where the policy is enforced in practice, because many systems are set differently from what the document says. UnityCare IT helps healthcare organizations align policy with real configuration, including password managers and multi-factor authentication, and we are happy to review your current settings with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172