Walk through almost any nursing station and you may find a sticky note with a password on a monitor. Staff are not being careless for fun. They are working under time pressure, logging in dozens of times a shift, with rules that sometimes make little practical sense.
A good password policy accepts reality. It protects accounts while respecting how care is delivered. Current guidance from NIST, in its digital identity guidelines (SP 800-63B), has moved away from some older habits, and that is good news for busy teams.
NIST recommends, in summary:
Favor length over complexity. Long passphrases are stronger and easier to remember than short strings of odd symbols.
Do not force frequent periodic password changes with no sign of compromise. Forced rotation tends to produce predictable variations, such as adding a number to the end.
Do change a password when there is evidence it has been compromised.
Check new passwords against lists of commonly used or previously breached passwords.
Allow password managers and pasting, rather than blocking them.
Your own requirements may come from payers, insurers or contracts, so confirm them, but the principles above are a sound starting point.
Encourage three or four unrelated words, such as a short sentence nobody could guess. Aim for at least twelve to sixteen characters.
Shared logins make audit trails useless and violate the principle of individual accountability. Make individual login fast instead, with tools such as badge tap, single sign-on or fast user switching at shared workstations.
A good password plus a second factor beats a perfect password alone. Cover email and remote access first.
A company-approved password manager lets staff keep strong unique passwords without memorizing them. It is a better answer than a sticky note.
Many systems can reject passwords like "Summer2025!" or the facility name. Turn that feature on where available.
Limit repeated failed attempts, but not so harshly that an attacker can lock out your entire staff on purpose, and not so tightly that a night-shift nurse is stuck at 3 a.m.
A clear process for forgotten passwords reduces workarounds. Verify identity before resetting, since attackers often phone helpdesks pretending to be employees.
In clinical areas, logging in with a long password dozens of times per shift is unrealistic. Options include proximity badges, fingerprint readers where permitted, or short automatic session timeouts combined with fast re-authentication. Choose methods with clinical staff input and test them on a real shift.
Never reuse a work password anywhere else
Never type a password into a site reached from an email link
Report immediately if a password may have been exposed
Do not write passwords down in view of others
These deserve extra care. Use long, random passwords stored in a vault, give administrators separate accounts for admin work, and review who holds them regularly. Remove vendor accounts that are no longer in use.
Even a good policy meets edge cases. Float staff may need access on short notice, agency nurses may start in the middle of a shift, and a locked account at 3 a.m. should not leave a unit without charting tools. Decide in advance who can approve a temporary exception, how it is logged, and when it expires. Writing these paths down keeps people from inventing their own, and it gives you a record to review for patterns that suggest the policy itself needs adjusting.
Put the policy in writing, include it in HIPAA training, and review it annually. If you apply sanctions for violations, apply them consistently, but start with education and better tools, because most violations come from poor design, not bad intent.
UnityCare IT helps healthcare organizations draft practical access policies and deploy the tools that support them, from password managers to single sign-on. If your staff are working around your current rules, that is a signal worth examining together.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172