Few topics generate more eye-rolling in a nursing facility than passwords. Staff sign in dozens of times a shift, often on shared workstations, with gloves on and call lights going. Policies that require complicated passwords changed every thirty days tend to produce sticky notes under keyboards and passwords that differ by one digit.
The good news is that current guidance has moved toward approaches that are both safer and easier for people. This post explains what to put into a realistic policy.
The NIST digital identity guidelines (SP 800-63B) recommend favoring length over complexity, checking new passwords against lists of known compromised passwords, and avoiding forced periodic changes unless there is evidence of compromise. That reflects research showing that frequent mandatory changes lead people to choose weaker, predictable patterns.
A passphrase is a string of several unrelated words, such as a sentence fragment that only the user would remember. It is long, which makes it hard to guess by brute force, and easier to remember than a short mix of symbols. Staff can type it quickly on a keyboard, which matters on busy shifts.
Good passphrases:
Use at least fourteen to sixteen characters
Combine several unrelated words rather than a famous quote or song lyric
Are not based on the facility name, a resident name, a birthday or a season and year
Are unique to each account
Require a longer minimum, and do not cap the maximum length so low that passphrases do not fit. Allow spaces and any characters.
Many identity systems can reject common passwords and those found in breach lists. This does more good than a complexity rule.
The strongest improvement to any password policy is a second factor. Prioritize email, remote access, the EHR and any admin tools.
Staff who use email, payroll portals, pharmacy tools and supplier sites cannot realistically remember dozens of unique passphrases. A business password manager lets them remember a single strong passphrase and store the rest securely. It also lets leadership revoke access when someone leaves.
Require a change after a suspected compromise, after a staff departure for any shared account, or when a vendor reports a breach. Do not force changes on a calendar without a reason.
Shared computers on nursing units are a real challenge. Consider:
Individual logins for every user, rather than a shared unit account, so access is traceable
Badge tap or proximity card sign-in with a PIN, where your systems support it, to speed access
Automatic session locking after a short idle time, balanced with workflow needs
Fast user switching so one person can sign out and the next can sign in without a full restart
HIPAA's Security Rule requires unique user identification and automatic logoff as addressable or required specifications, so shared logins can also create compliance issues.
Writing passwords on notes near monitors or on the back of badges
Reusing a work password for personal accounts
Sharing logins to cover a coworker's break
Sending passwords by email or text
Keeping default passwords on printers, cameras and network devices
Explain the why. Staff accept change more readily when they understand that the goal is to make logging in easier and safer, not to add hurdles. Offer short, hands-on sessions during shift overlap, publish a one-page guide, and have a clear contact for lockouts so people are not stuck during a med pass.
UnityCare IT can help you set up MFA, a password manager and sign-in processes that fit nursing unit workflows. If your policy has not been reviewed in several years, a quick assessment is a good place to begin.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034