Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: The Almighty Password

So many passwords for so many accounts – what is a person to do? Are you thinking “I’m SO tired of hearing about passwords or having to create them, and not able to use four characters anymore?” That’s the good news!

Lets start with password length. Statistically, a 7-character password can be cracked in four seconds. Startling, right?

Next – using the same password for every account. This is a no-brainer for hackers. Why stop at one account when the keys to the kingdom might open numerous accounts containing financial information, social security numbers, driver’s licenses, and ultimately, Protected Health Information (PHI) that can be sold on the Black Market for a lot of money? Office for Civil Rights (OCR) recently stated that a complete medical record of one person could fetch $10,000 on the Dark Web.

Why should you not use personal information in your password? Think about exactly what you may be divulging in a password: your kid’s names, your home address, your birthdate. Already you may have given up Personally Identifiable Information or worse, identifiers in your PHI.

Some helpful tips:

  • Passphrases are WAY better than passwords.
  • Never use a password for multiple accounts.
  • Create passwords or passphrases that are at least 12-14 characters.
  • Do not store passwords in obvious places and never save in browsers.
  • NEVER share your passwords or use an account that has shared passwords, especially when dealing with PHI.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP