IT4EyesAN STS COMPANY
← Back to Blog

The Password Policy Your Eye Care Office Should Actually Have

The Password Policy Your Eye Care Office Should Actually Have

Password policies have a reputation for making everyone's workday harder.

That is especially true in a busy eye care practice.

Staff may move between the EHR, scheduling, billing, optical systems, email, imaging applications, insurance portals, and vendor websites throughout the day. If every system has different password rules—and employees are forced to change passwords constantly—it can feel less like cybersecurity and more like another obstacle between the team and the patient.

That frustration can also lead to bad habits.

Passwords get written on sticky notes.

Employees create predictable variations such as Practice1, Practice2, and Practice3.

Several people start using the same account because it is easier.

The goal of a password policy should not be to create the most complicated rules possible.

It should be to protect patient information and practice systems without creating so much friction that employees look for ways around the policy.

And that starts with understanding what HIPAA actually requires—and what it does not.

First: HIPAA Does Not Give You a Standard Password Formula

There is a lot of confusion around "HIPAA password requirements."

HIPAA does not prescribe one universal password length, a specific combination of uppercase letters and symbols, or a rule requiring every password to change every 60 or 90 days.

The Security Rule is designed to be technology-neutral.

That does not mean passwords are optional or unimportant. It means practices need appropriate procedures for controlling access to electronic protected health information, or ePHI, based on their environment and risk.

For an eye care office, the strongest password policy usually focuses less on complicated formulas and more on individual accountability, strong unique credentials, secure storage, multi-factor authentication, and sensible access management.

Rule 1: Every User Should Have an Individual Account

Shared workstations are common in eye care.

Shared credentials should not be.

A front-desk computer may be used by several employees throughout the day. The same may be true for an exam-room workstation.

But when the system contains ePHI, HIPAA requires unique user identification so activity can be identified and tracked to an individual user. HHS specifically states that covered entities cannot assign the same log-on or user ID to multiple employees accessing a system that maintains ePHI.

So an account named FrontDesk used by six people creates more than an inconvenience.

It removes accountability.

If patient information is viewed, changed, exported, or accessed improperly, you want to know which individual account performed the action.

Unique accounts also make employee transitions easier. When someone leaves the practice, their access can be disabled without changing a password used by the entire office.

A computer can be shared.

An identity should not be.

Rule 2: Stop Relying on Constant Password Changes

One of the most persistent password myths is that changing passwords every 60 or 90 days automatically makes them safer.

Current NIST guidance recommends against arbitrary periodic password changes. Instead, a password should be changed when there is evidence that the credential has been compromised.

Why?

Because frequent forced changes often lead people to create predictable patterns.

Vision2026! becomes Vision2026!!.

Then Vision2027!.

Or employees make only the smallest change necessary because they know they will have to remember another password again soon.

A better approach is to encourage long, unique passwords or passphrases and require changes when there is a meaningful reason—such as suspected compromise, exposed credentials, or a security incident.

Of course, individual applications or vendors may impose their own password-expiration requirements. Your practice may have to follow those where required.

But your internal password policy does not need to make arbitrary expiration the centerpiece of security.

Rule 3: Every Important Account Needs a Unique Password

Reusing passwords is dangerous because one compromised account can create access to others.

Imagine an employee uses the same password for:

  • Email

  • A billing portal

  • A vendor website

  • A cloud application

If one outside service is breached and that password becomes exposed, an attacker may try the same credentials elsewhere.

This is one reason unique passwords matter.

But asking employees to memorize ten or fifteen complicated passwords is not realistic.

That is where password managers can help.

Rule 4: Use an Approved Password Manager

A business-grade password manager can store credentials in an encrypted vault and generate strong, unique passwords for different systems.

That solves one of the biggest practical problems with good password hygiene:

Employees no longer need to memorize every credential.

Instead of using one familiar password everywhere—or maintaining a handwritten list next to the monitor—the employee can use unique credentials across approved systems.

Password managers can also help practices control the secure sharing of credentials when sharing is genuinely necessary.

For example, there may be a vendor portal with only one organizational account available.

Rather than texting or emailing that password between employees, an approved password-management platform may provide a safer way to control access.

The key is to choose and manage the password manager as part of the practice's security program—not simply let employees pick whichever personal tool they prefer.

Rule 5: Use MFA Where It Matters

Multi-factor authentication, or MFA, requires more than one method of verifying identity.

A password might be combined with an authentication application, security key, biometric factor, or another approved method.

That matters because a stolen password alone may no longer be enough to access the account.

For an eye care practice, MFA deserves particular attention for:

  • Email

  • Administrative accounts

  • Cloud applications

  • Financial systems

  • Systems containing sensitive information

As of September 2026, the current HIPAA Security Rule does not impose a universal MFA requirement across all systems. However, HHS has proposed significant Security Rule changes that would require MFA in most circumstances, with limited exceptions. That proposal has not yet become the current rule.

Regardless of the regulatory timeline, MFA is an important security control for high-risk accounts.

Rule 6: Unattended Workstations Should Protect Themselves

Imagine a staff member steps away from the front desk to help a patient.

The EHR remains open.

Patient names and information are visible on the monitor.

No malicious hacker is required for that to become a privacy problem.

HIPAA includes automatic logoff as an addressable implementation specification. Where it is reasonable and appropriate, organizations should use electronic procedures that end a session after a predetermined period of inactivity.

The exact timeout is not universally dictated by HIPAA.

It should make sense for the practice environment.

Too long, and sensitive information may remain accessible.

Too aggressive, and staff may spend the entire day logging back into applications, creating unnecessary frustration.

This is another example of why security needs to account for real clinical workflow.

Rule 7: Password Security Includes Employee Offboarding

A strong password policy is also an access policy.

When an employee leaves, the practice should have a defined process for removing access promptly.

That may involve:

  • Disabling the employee's account

  • Removing email access

  • Revoking remote access

  • Removing password-manager permissions

  • Updating shared credentials when necessary

  • Removing access from vendor systems

  • Recovering practice-owned devices

  • Reviewing administrative privileges

Former employees should not retain access simply because nobody remembered every application they used.

This is particularly important in eye care because practices often work with numerous vendor systems beyond the primary EHR.

A Practical Password Policy Checklist

Your practice should be able to answer:

  • Does each workforce member have a unique account where required?

  • Are passwords unique across systems?

  • Are long, strong passwords or passphrases encouraged?

  • Are arbitrary password changes avoided unless a system requires them?

  • Is there an approved password manager?

  • Is MFA enabled on high-risk accounts where appropriate?

  • Are unattended workstations automatically protected?

  • Is there a documented employee offboarding process?

  • Who reviews user access and administrative privileges?

  • What happens when a password is suspected to be compromised?

If nobody knows the answers, the password policy probably needs work.

FAQ: Password Policies and HIPAA

Does HIPAA require passwords to change every 90 days?

No. HIPAA does not establish a universal 90-day password-expiration rule. Current NIST guidance recommends against arbitrary periodic changes and favors changing passwords when compromise is suspected or known.

Can several employees share one EHR login?

For systems maintaining ePHI, HIPAA requires unique user identification so access and activity can be tied to an individual user.

Does HIPAA currently require MFA?

Not universally under the current Security Rule. HHS has proposed changes that would require MFA in most circumstances, but those changes remain proposed as of September 2026.

Does HIPAA specify how long a password must be?

HIPAA does not prescribe one universal password length. Your practice should use reasonable safeguards based on risk and current security practices.

Make the Policy Secure Enough to Follow

A password policy is only useful if people can realistically follow it.

Eye care staff are moving between patients, exam rooms, phone calls, diagnostic systems, insurance work, and administrative tasks all day.

Security should protect those workflows without encouraging shortcuts.

That means fewer outdated rules and more focus on what actually matters:

Individual accounts. Unique passwords. Secure credential storage. MFA. Appropriate workstation locking. Prompt access removal.

IT4Eyes helps eye care practices manage the broader access-control environment behind those policies—from user accounts and MFA to workstation security, vendor access, employee offboarding, and HIPAA-related IT safeguards.

Because the best password policy is not the one with the most rules.

It is the one that makes secure behavior the easiest behavior for your team to follow.

Book A 10-Minute Conversation

Book A 10-Minute Conversation Or Call And Speak To An IT Expert Today

Get In Touch