Skip to main content
Every person has their own login to every system. This is a named requirement of the HIPAA Security Rule, not a preference. It’s how we know who did what, and it’s how we can remove one person’s access without disrupting anyone else’s.

Rules

  • Never share your password with anyone, including a colleague who’s locked out, a manager, or someone claiming to be from a vendor.
  • Never use someone else’s login, even with their permission, even for a minute.
  • Never reuse a practice password on any other site.
  • Use a password manager. Long, unique, generated passwords for everything. The practice will tell you which manager it supports.
  • Turn on two-factor authentication everywhere. Use an authenticator app, not SMS, wherever the system allows it.
  • Change your password immediately if you think it’s been exposed, and tell Zack.

Password standards

At least 14 characters, or a generated password from your password manager. No personal information, no dictionary words alone, no pattern you use elsewhere.

Shared accounts

A few systems are unavoidably shared (for example, a shared front-office phone line). Those are documented by Zack, access is limited to the people who need them, and credentials live in the practice’s password manager, never in a message or a sticky note. If you find a shared login that isn’t documented, tell Zack.

Locked out

If you’re locked out, contact Zack. Don’t ask a colleague to log in for you. A few minutes of delay is fine. A shared session isn’t.

When you leave

Your accounts are disabled on your last day, and any shared credentials you knew are rotated. See Offboarding and access revocation.