• Listen Live NOW!
  • On Demand
  • Ways to Listen
  • All Shows
    • Radio Shows
      • Digital Health Talks
      • Health Cent$
      • Health Stealth Radio
      • Health UnaBASHEd
      • Healthcare De Jure
      • Healthcare IT Today
      • News You Can Use
      • PopHealth Week
      • Talking the Walk
      • The Tate Chronicles
      • The Virtual Shift
      • This Just In Radio Show
      • Trending NOW
      • Value-Based Care Insights
      • We Have Trust Issues
      • What’s My Tagline?
    • Podcast Shows
      • Ambulatory Healthcare Today
      • Ask the Educator
      • FINN Voices
      • Healthcare for Humans
      • HealthLaw HotSpot
      • Inside the Revival
      • Revenue Cycle Optimized
      • Selling to Healthcare
      • The Handoff
      • The Healthtech Marketing Show
      • The MRO Exchange
      • Unscripted The AMCP Podcast
    • Monthly/Limited Series Podcasts
      • AI Amplified
      • Take a Listen
      • Tell Me Where IT Hurts
      • The CereCore Podcast
      • The Dish on Health IT
      • Voices of Self Funding
  • Playlists
  • NursesNOW
    • Nursing News
      • Organizations
      • Podcasts
  • Conferences
  • Request a Media Kit
Event Calendar
HealthcareNOWradio.comHealthcareNOWradio.com
  • Listen Live NOW!
  • On Demand
  • Ways to Listen
  • All Shows
    • Radio Shows
      • Digital Health Talks
      • Health Cent$
      • Health Stealth Radio
      • Health UnaBASHEd
      • Healthcare De Jure
      • Healthcare IT Today
      • News You Can Use
      • PopHealth Week
      • Talking the Walk
      • The Tate Chronicles
      • The Virtual Shift
      • This Just In Radio Show
      • Trending NOW
      • Value-Based Care Insights
      • We Have Trust Issues
      • What’s My Tagline?
    • Podcast Shows
      • Ambulatory Healthcare Today
      • Ask the Educator
      • FINN Voices
      • Healthcare for Humans
      • HealthLaw HotSpot
      • Inside the Revival
      • Revenue Cycle Optimized
      • Selling to Healthcare
      • The Handoff
      • The Healthtech Marketing Show
      • The MRO Exchange
      • Unscripted The AMCP Podcast
    • Monthly/Limited Series Podcasts
      • AI Amplified
      • Take a Listen
      • Tell Me Where IT Hurts
      • The CereCore Podcast
      • The Dish on Health IT
      • Voices of Self Funding
  • Playlists
  • NursesNOW
    • Nursing News
      • Organizations
      • Podcasts
  • Conferences
  • Request a Media Kit

NIST Guidelines for Strong Passwords

August 17, 2023 Posted by Industry Expert Compliance Privacy Security

By Art Gross, President and CEO, HIPAA Secure Now!
X: @HIPAASecureNow
Read other articles by this author

The healthcare industry relies heavily on technology to store, manage, and access patient information. And one fundamental aspect of protecting patient information is using strong passwords or passphrases in line with the National Institute of Standards and Technology (NIST) guidelines.

The Significance of Strong Passwords

Passwords act as the first defense against unauthorized access to sensitive medical records, financial data, and other confidential information. Unfortunately, many cyberattacks succeed due to weak passwords, such as easily guessable combinations or reused passwords across multiple accounts. For healthcare providers, the ramifications of a data breach can be catastrophic, resulting in financial losses, legal liabilities, damaged reputation, and, most importantly, jeopardized patient safety.

NIST Standards for Passwords

The National Institute of Standards and Technology (NIST) is a renowned authority on cybersecurity best practices. Their guidelines for creating and managing passwords aim to enhance security while promoting usability. Here are some key aspects of the NIST standards that healthcare providers should adhere to:

  1. Password Length: NIST recommends using passwords with a minimum length of 12 characters. Longer passwords are generally more secure, as they increase the complexity and make them harder for attackers to crack.
  2. Complexity is Out, Long Passphrases are In: NIST discourages the use of complex password requirements, such as mandating uppercase letters, numbers, and symbols. Instead, they advocate for using long passphrases. A passphrase is a sequence of random words or a sentence that is easy for users to remember but difficult for attackers to guess.
  3. Password Blacklists: NIST advises against using common and easily guessable passwords (e.g., “123456” or “password”). Implementing a password blacklist can prevent users from choosing weak passwords.
  4. Password Rotation is Optional: Historically, organizations often forced users to change their passwords frequently. However, NIST found this practice can lead to weaker passwords being used. Instead, it’s better to encourage the use of unique and strong passwords or passphrases that users do not have to change regularly unless there is a suspicion of compromise.
  5. Multi-Factor Authentication (MFA): NIST strongly advocates for the implementation of Multi-Factor Authentication, which requires users to provide two or more forms of identification before gaining access to an account. MFA significantly enhances security and should be used in conjunction with strong passwords.
  6. Password Managers: NIST suggests using password managers, which are secure tools that generate and store complex passwords for various accounts. Password managers reduce the burden of remembering multiple passwords while improving overall security.

The digital transformation in healthcare has brought immense benefits to patient care. But it has also exposed it to new cybersecurity challenges. Implementing strong passwords or passphrases following the NIST standards is a fundamental step in protecting patient data and safeguarding the reputation of healthcare providers. By adopting best practices and staying vigilant, healthcare providers can fortify their cybersecurity defenses.

This article was originally published on HIPAA Secure Now! and is republished here with permission.

Tags: Art GrossHIPAA Secure Now!NISTpasswords

Radio for the Healthcare Industry

No HTML5 audio playback capabilities for this browser. Use Chrome Browser!

Categories

Get Our News Digest


Thank you!

You have successfully joined our subscriber list.

.

Upcoming Events

Dec 10
December 10 - December 12

ATA EDGE Policy Conference

Washington
Jan 6
January 6, 2026 - January 9, 2026

CES 2026

Feb 8
February 8, 2026 - February 11, 2026

2026 AHA Rural Health Care Leadership Conference

San Antonio
View Calendar

About HealthcareNOWRadio.com

HealthcareNOWradio.com is an Internet radio station operated and produced as part of Answers Media Network. The station offers interviews, and commentary from industry leaders in healthcare and health information technology, as well as originally produced programming hosted by industry leaders. Listen on any device 24/7. You can also subscribe to get notification when a new show airs.

Sign Up for Our e-News Digest

Get notified when a new show airs or when your favorites are available as podcasts. Sign up here

Connect with Us

Request a Media Kit

Contact Us

Book a Guest

Visit Health IT Answers

©2025 Answers Media Company, LLC

  • Our Privacy Policy
  • Our Guests and Recording Policy
Prev Next