Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Securing Passwords

Why Password Security Matters for HIPAA Compliance

We discuss all the time the importance of password security measures, i.e., password length, restricting the reuse of the last several passwords, passphrases versus passwords or even one’s name (first initial, last name), account lockout of a system after so many failed password login attempts, never using the same password for all accounts (this is a BIG one!).

TL;DR – HIPAA Password Security Essentials:

  • Average person manages 160-200 passwords – impossible to remember all
  • NEVER reuse passwords across accounts – threat actors will exploit this
  • Use Password Managers to securely store and generate strong passwords
  • Enhanced features include multi-factor authentication (MFA) and dark web monitoring
  • Free and paid options available: 1Password, Keeper, Bitwarden, Dashlane, NordPass

The Challenge of Managing Hundreds of Passwords

What about where we are storing our passwords? In today’s internet environment the average person has anywhere from 160-200 passwords for their personal and business accounts. No matter how amazing your memory is, it would be impossible to remember all passwords being used, and again as a reminder, do NOT use the same password for all or most accounts. Why does this matter? Once a threat actor gains access to one of your accounts be rest assured they will attempt to access more of your personal or business accounts using the same password – that’s a no-brainer.

Password Managers: A Secure Solution

Password Managers are software solutions that securely store passwords and create stronger passwords reducing the risk of weak or reused passwords, simplifying the process of creating and managing secure online accounts all while protecting your digital identity and valuable information. With most Password Managers there are enhanced security features such as multi-factor authentication (MFA) and dark web monitoring.

Not all Password Managers cost money or require a subscription. Some Password Managers to look into:

  • 1Password
  • Keeper
  • Bitwarden
  • Dashlane
  • NordPass

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.