Password Hygiene & MFA
Passwords are the keys to your organization’s data. Learn how to create strong passwords, use password managers, and leverage MFA to stop attackers even when passwords are stolen.
What You Will Learn
Passwords are the keys to your organization’s data. This module covers how to create strong passwords, why password managers are essential, and how multi-factor authentication (MFA) stops attackers even when passwords are stolen.
- Password fundamentals: what makes a password strong or weak
- Password managers: why you should use one and how they work
- Multi-factor authentication (MFA): the single most effective security control
- Common password mistakes: habits that put your organization at risk
- Passphrases: a better way to create passwords you can actually remember
Why Passwords Matter
Weak passwords are one of the easiest ways for attackers to break into your accounts. When an attacker gets your password, they can access your email, your files, your patient records, your client data, and your financial systems. From one compromised account, they can often reach others.
The challenge is that you likely have dozens of accounts, each needing a password. No one can remember that many strong, unique passwords. That is where password managers and MFA come in.
Quick Check
Which of these passwords is the strongest?
What Makes a Password Strong
Strong Password Checklist
- Length over complexity. A 16+ character password is stronger than an 8-character password with symbols. Every additional character makes cracking exponentially harder.
- Unique for every account. Never reuse passwords. If one account is breached, attackers will try that password on every other account.
- No personal information. Avoid names, birthdays, pet names, and company names. These are easy to find on social media.
- Use passphrases. Combine 4-5 random words like purple-elephant-window-festival. They are long, strong, and memorable.
- No patterns. Avoid keyboard patterns (qwerty, 12345678) and seasonal passwords (Summer2026, Spring2026).
Password Managers: Your Security Vault
A password manager is a tool that generates, stores, and auto-fills strong, unique passwords for every account. You only need to remember one master password. The password manager handles the rest.
STM recommends and can deploy password managers for your organization. Popular options include Bitwarden, 1Password, and LastPass. They work across all your devices and browsers.
Quick Check
Your colleague says they use the same password for their email and their EHR login because it is easier. What should you tell them?
Multi-Factor Authentication (MFA)
MFA requires two forms of verification to log in: something you know (your password) and something you have (your phone, an app, or a security key). Even if an attacker steals your password, they cannot log in without the second factor.
MFA is the single most effective security control you can implement. Microsoft reports that MFA blocks over 99% of automated account attacks. If you implement only one security measure from this training, make it MFA.
Types of MFA
- Authenticator app (recommended): Apps like Microsoft Authenticator or Google Authenticator generate a 6-digit code that refreshes every 30 seconds. No internet connection needed.
- Text message (SMS): A code is texted to your phone. Less secure than an app because SMS can be intercepted, but better than no MFA.
- Security key (most secure): A physical USB device like a YubiKey that you tap to verify. Nearly impossible to phish.
- Push notification: Your phone shows a prompt asking you to approve or deny the login. Fast and easy, but only approve prompts you initiated.
Quick Check
You receive an MFA push notification on your phone asking you to approve a login, but you are not trying to log in to anything. What should you do?
Common Password Mistakes to Avoid
Password Mistakes That Put You at Risk
- Reusing passwords across accounts. If one is stolen, all are compromised.
- Writing passwords on sticky notes. Especially on your monitor where anyone can see them.
- Sharing passwords with colleagues. Every person should have their own account. Shared accounts make it impossible to track who did what.
- Using personal passwords for work accounts. If your personal account is breached, your work accounts are too.
- Never changing passwords after a breach. If you hear about a breach at a service you use, change that password immediately.
How This Looks in Your Industry
Healthcare Practices
EHR systems, patient portals, and billing platforms all require passwords. HIPAA requires unique user IDs and passwords for each person. Shared passwords violate HIPAA because you cannot track who accessed patient records. MFA on your EHR is one of the strongest HIPAA safeguards.
Legal Firms
Case management systems and client portals contain privileged information. Shared passwords can waive attorney-client privilege by making it impossible to prove who accessed what. MFA on email is essential because email is the primary communication channel for client matters.
Nonprofits
Donor databases, grant portals, and accounting systems contain sensitive financial and personal data. Password managers are affordable (some are free for small teams) and dramatically improve security without adding burden to volunteers.
Daycares and Schools
Student information systems, parent communication apps, and state reporting portals require strong access controls. COPPA and FERPA require reasonable security measures. MFA on staff accounts is a simple, effective way to meet those requirements.
Key Takeaways
- Use passphrases: 4-5 random words are stronger and easier to remember than short complex passwords.
- Never reuse passwords. Every account gets a unique password. A password manager makes this easy.
- MFA blocks over 99% of automated account attacks. It is the single most effective security control.
- Never approve an MFA prompt you did not initiate. Deny it and report it immediately.
- Password managers generate, store, and auto-fill strong passwords. You only remember one master password.
Module Quiz
Complete this quiz to test your understanding of the module. Answers are provided below each question.
1. What is the main benefit of using a password manager?
2. MFA blocks what percentage of automated account attacks according to Microsoft?
3. You want to create a strong password you can actually remember. Which approach is best?
4. A colleague asks to borrow your EHR login because theirs is not working. What should you do?
5. Which type of MFA is most secure?
Module 02 of 10 – Cybersecurity Essentials Training
