Passwords That Work in a Real Clinic

Shared logins, sticky notes, and reused passwords are not laziness — they are busy people coping. Here is a password setup your staff will actually use, and that HIPAA actually accepts.

Dental hygienist with a patient — protecting health data in daily care

The password problems every clinic has

Walk into almost any small clinic and you will find the same three problems: one shared login everyone uses, passwords on sticky notes under keyboards, and the same password reused across the EHR, email, and billing. None of this is malice — it is people trying to get through a busy day. But each one is a hole, and HIPAA’s Security Rule specifically requires unique user identification for a reason: when something goes wrong, you must be able to tell who did what.

What actually works in a real clinic

  • One login per person. No exceptions. Shared accounts mean shared blame — when six people use “frontdesk,” an audit log is useless and a terminated employee’s access never really ends. Individual accounts with fast user switching cost seconds, not minutes.
  • Use a password manager. This is the single change that fixes the sticky-note problem. Staff remember one strong master password; the manager creates and fills long, unique passwords for everything else. Pick one with business features — shared vaults for role accounts, and the ability to revoke access when someone leaves.
  • Role accounts get vaulted, not memorized. Some shared access is legitimate — the billing login, the supply ordering account. Those credentials live in the password manager’s shared vault, never on a note taped to the monitor, and the vault password changes when staff turns over.
  • Length beats complexity. A long passphrase staff can actually remember — four or five random words — beats a short cryptic password they write down. Fourteen characters minimum is the modern baseline.
  • Never reuse across systems. The EHR password, the email password, and the personal Facebook password must all be different. Breaches of one site fuel attacks on the others — attackers count on reuse.

Making it stick with non-technical staff

Install it for them. Do not send a link and hope. Sit with each person for ten minutes: install the manager, set the master passphrase, save their first three logins. Adoption happens in that ten minutes or not at all.

Explain the why once, plainly. “A Coastal Bend practice got hit by ransomware recently. Stolen passwords are how these attacks start. This is how we make sure it is not us.” Real stakes beat policy lectures.

Collect the sticky notes yourself. Announce the amnesty: bring every written-down password, no questions asked, and it goes in the manager. Then watch for new ones for a month.

Pair it with MFA. A password manager plus multi-factor authentication on every system means a stolen password alone gets an attacker nothing. The two controls multiply each other.

The day someone leaves: the offboarding checklist

Every departure — friendly or not — runs the same checklist, the same day. Disable their user accounts across the EHR, email, and billing systems. Remove them from shared password vaults. Change any shared or role passwords they knew. Collect hardware keys, badges, and building keys. Remove their MFA enrollments and their phone from any device management. Confirm their email is forwarded or archived per your retention policy, not silently deleted. Print the checklist, initial each line, file it. For involuntary terminations, run the technical steps before the conversation, not after — accounts disabled first, meeting second. “We’ll get to it next week” is how a former employee’s login stays live for six months — and under HIPAA, every day of that is your liability, not theirs.

What to do Monday morning

Count the shared accounts. List every login in the clinic that more than one person uses, and note which systems they reach. That list is your conversion plan — each one becomes individual accounts plus a vaulted role credential. Start with the EHR and email; finish the rest within the month.

Run the checklist backwards as an audit: pick three former employees and verify every item was actually done. If you find a live account for someone who left months ago, disable it now and treat the gap as a finding in your next risk assessment — that is exactly what the assessment is for. Then make the checklist part of the exit process itself — IT items alongside the final paperwork, so nothing depends on remembering next week.

Not sure where your practice stands?

Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

Is a shared front-desk login really a HIPAA problem?

Yes. The Security Rule requires unique user identification so access to patient information can be traced to an individual. A shared account makes that impossible — and it means a former employee’s access survives their departure.

What is a password manager, exactly?

Software that creates, stores, and fills in strong unique passwords for every site and system, protected by one master passphrase only the user knows. Staff stop reusing passwords because they stop needing to remember them.

What should we do when an employee leaves?

Immediately: disable their accounts, change any shared or role passwords they knew, remove them from the password manager vaults, and collect any hardware keys. This should be a written checklist, run the same day — not ‘when we get to it.’

Are passphrases really better than complex passwords?

For humans, yes. Four or five random words are long enough to resist guessing but memorable enough that staff do not write them down. Length is what defeats automated attacks; complexity requirements mostly defeat the humans.

Should the office manager know everyone’s passwords?

No. With individual accounts and a password manager, nobody needs anyone else’s password. Admins can reset access without ever seeing the password itself. ‘Just in case’ password lists are a breach waiting to happen.