> ## Documentation Index
> Fetch the complete documentation index at: https://handbook.helendelovely.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Passwords and User Accounts

> One person, one login. Never shared, never reused.

Every person has their own login to every system. This is a named requirement of the HIPAA Security Rule, not a preference. It's how we know who did what, and it's how we can remove one person's access without disrupting anyone else's.

## Rules

* **Never share your password** with anyone, including a colleague who's locked out, a manager, or someone claiming to be from a vendor.
* **Never use someone else's login**, even with their permission, even for a minute.
* **Never reuse** a practice password on any other site.
* **Use a password manager.** Long, unique, generated passwords for everything. The practice will tell you which manager it supports.
* **Turn on two-factor authentication** everywhere. Use an authenticator app, not SMS, wherever the system allows it.
* **Change your password immediately** if you think it's been exposed, and tell Zack.

## Password standards

At least 14 characters, or a generated password from your password manager. No personal information, no dictionary words alone, no pattern you use elsewhere.

## Shared accounts

A few systems are unavoidably shared (for example, a shared front-office phone line). Those are documented by Zack, access is limited to the people who need them, and credentials live in the practice's password manager, never in a message or a sticky note. If you find a shared login that isn't documented, tell Zack.

## Locked out

If you're locked out, contact Zack. Don't ask a colleague to log in for you. A few minutes of delay is fine. A shared session isn't.

## When you leave

Your accounts are disabled on your last day, and any shared credentials you knew are rotated. See [Offboarding and access revocation](/leaving/offboarding-and-access-revocation).
