Writing a Password Policy That Staff Will Actually Follow

Walk through almost any nursing station and you may find a sticky note with a password on a monitor. Staff are not being careless for fun. They are working under time pressure, logging in dozens of times a shift, with rules that sometimes make little practical sense.

A good password policy accepts reality. It protects accounts while respecting how care is delivered. Current guidance from NIST, in its digital identity guidelines (SP 800-63B), has moved away from some older habits, and that is good news for busy teams.

What Current Guidance Says

NIST recommends, in summary:

Favor length over complexity. Long passphrases are stronger and easier to remember than short strings of odd symbols.

Do not force frequent periodic password changes with no sign of compromise. Forced rotation tends to produce predictable variations, such as adding a number to the end.

Do change a password when there is evidence it has been compromised.

Check new passwords against lists of commonly used or previously breached passwords.

Allow password managers and pasting, rather than blocking them.

Your own requirements may come from payers, insurers or contracts, so confirm them, but the principles above are a sound starting point.

Elements of a Workable Policy

Use passphrases

Encourage three or four unrelated words, such as a short sentence nobody could guess. Aim for at least twelve to sixteen characters.

Never share accounts

Shared logins make audit trails useless and violate the principle of individual accountability. Make individual login fast instead, with tools such as badge tap, single sign-on or fast user switching at shared workstations.

Use multifactor authentication

A good password plus a second factor beats a perfect password alone. Cover email and remote access first.

Provide a password manager

A company-approved password manager lets staff keep strong unique passwords without memorizing them. It is a better answer than a sticky note.

Block known-bad passwords

Many systems can reject passwords like "Summer2025!" or the facility name. Turn that feature on where available.

Set lockout rules sensibly

Limit repeated failed attempts, but not so harshly that an attacker can lock out your entire staff on purpose, and not so tightly that a night-shift nurse is stuck at 3 a.m.

Make reset easy and secure

A clear process for forgotten passwords reduces workarounds. Verify identity before resetting, since attackers often phone helpdesks pretending to be employees.

Address Shared Workstation Reality

In clinical areas, logging in with a long password dozens of times per shift is unrealistic. Options include proximity badges, fingerprint readers where permitted, or short automatic session timeouts combined with fast re-authentication. Choose methods with clinical staff input and test them on a real shift.

What to Teach Staff

Never reuse a work password anywhere else

Never type a password into a site reached from an email link

Report immediately if a password may have been exposed

Do not write passwords down in view of others

Service and Administrator Accounts

These deserve extra care. Use long, random passwords stored in a vault, give administrators separate accounts for admin work, and review who holds them regularly. Remove vendor accounts that are no longer in use.

Handling Exceptions Gracefully

Even a good policy meets edge cases. Float staff may need access on short notice, agency nurses may start in the middle of a shift, and a locked account at 3 a.m. should not leave a unit without charting tools. Decide in advance who can approve a temporary exception, how it is logged, and when it expires. Writing these paths down keeps people from inventing their own, and it gives you a record to review for patterns that suggest the policy itself needs adjusting.

Review and Enforcement

Put the policy in writing, include it in HIPAA training, and review it annually. If you apply sanctions for violations, apply them consistently, but start with education and better tools, because most violations come from poor design, not bad intent.

A Second Opinion

UnityCare IT helps healthcare organizations draft practical access policies and deploy the tools that support them, from password managers to single sign-on. If your staff are working around your current rules, that is a signal worth examining together.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172