Passwords vs Passphrases: A Practical Policy for Care Teams

Few topics generate more eye-rolling in a nursing facility than passwords. Staff sign in dozens of times a shift, often on shared workstations, with gloves on and call lights going. Policies that require complicated passwords changed every thirty days tend to produce sticky notes under keyboards and passwords that differ by one digit.

The good news is that current guidance has moved toward approaches that are both safer and easier for people. This post explains what to put into a realistic policy.

What current guidance says

The NIST digital identity guidelines (SP 800-63B) recommend favoring length over complexity, checking new passwords against lists of known compromised passwords, and avoiding forced periodic changes unless there is evidence of compromise. That reflects research showing that frequent mandatory changes lead people to choose weaker, predictable patterns.

Why passphrases work

A passphrase is a string of several unrelated words, such as a sentence fragment that only the user would remember. It is long, which makes it hard to guess by brute force, and easier to remember than a short mix of symbols. Staff can type it quickly on a keyboard, which matters on busy shifts.

Good passphrases:

Use at least fourteen to sixteen characters

Combine several unrelated words rather than a famous quote or song lyric

Are not based on the facility name, a resident name, a birthday or a season and year

Are unique to each account

Elements of a workable policy

1. Set a minimum length

Require a longer minimum, and do not cap the maximum length so low that passphrases do not fit. Allow spaces and any characters.

2. Block known bad passwords

Many identity systems can reject common passwords and those found in breach lists. This does more good than a complexity rule.

3. Require MFA for important systems

The strongest improvement to any password policy is a second factor. Prioritize email, remote access, the EHR and any admin tools.

4. Provide a password manager

Staff who use email, payroll portals, pharmacy tools and supplier sites cannot realistically remember dozens of unique passphrases. A business password manager lets them remember a single strong passphrase and store the rest securely. It also lets leadership revoke access when someone leaves.

5. Change passwords when there is a reason

Require a change after a suspected compromise, after a staff departure for any shared account, or when a vendor reports a breach. Do not force changes on a calendar without a reason.

Handling shared workstations

Shared computers on nursing units are a real challenge. Consider:

Individual logins for every user, rather than a shared unit account, so access is traceable

Badge tap or proximity card sign-in with a PIN, where your systems support it, to speed access

Automatic session locking after a short idle time, balanced with workflow needs

Fast user switching so one person can sign out and the next can sign in without a full restart

HIPAA's Security Rule requires unique user identification and automatic logoff as addressable or required specifications, so shared logins can also create compliance issues.

Mistakes to avoid

Writing passwords on notes near monitors or on the back of badges

Reusing a work password for personal accounts

Sharing logins to cover a coworker's break

Sending passwords by email or text

Keeping default passwords on printers, cameras and network devices

Roll it out gently

Explain the why. Staff accept change more readily when they understand that the goal is to make logging in easier and safer, not to add hurdles. Offer short, hands-on sessions during shift overlap, publish a one-page guide, and have a clear contact for lockouts so people are not stuck during a med pass.

UnityCare IT can help you set up MFA, a password manager and sign-in processes that fit nursing unit workflows. If your policy has not been reviewed in several years, a quick assessment is a good place to begin.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034