Password Best Practices Guide

REFERENCE / 2-PAGE GUIDE

Password Best Practices Guide

Step-by-step instructions for creating strong passwords, setting up a password manager, and enrolling in MFA.

Step 1: Create Strong Passwords

The strongest passwords are long and unique. Use passphrases: 4-5 random words combined are stronger than short passwords with special characters.

Use 16+ characters. Every additional character makes cracking exponentially harder.
Use passphrases. Combine 4-5 random words like river-cloud-pencil-thunder-window. Long, strong, and memorable.
Unique for every account. Never reuse passwords. If one account is breached, attackers try that password everywhere.
No personal information. Avoid names, birthdays, pet names, and company names. These are easy to find on social media.
No patterns. Avoid keyboard patterns (qwerty, 12345678) and seasonal passwords (Summer2026).

Step 2: Set Up a Password Manager

A password manager generates, stores, and auto-fills strong, unique passwords for every account. You only remember one master password.

Choose a password manager. STM recommends Bitwarden, 1Password, or LastPass. Contact us for organization-wide deployment.
Create a strong master password. This is the one password you must remember. Use a passphrase of 5+ random words.
Install the browser extension and mobile app. This lets the password manager auto-fill on all your devices.
Import or create entries for each of your accounts. Let the password manager generate strong passwords for each one.
Enable auto-lock so the password manager locks after a period of inactivity.
Never share your master password with anyone, including IT.

Step 3: Enable MFA (Multi-Factor Authentication)

MFA requires a second form of verification in addition to your password. Even if your password is stolen, attackers cannot log in without the second factor. MFA blocks over 99% of automated account attacks.

Check if MFA is available for each account. Most email, banking, and cloud services offer it.
Choose an authenticator app (recommended) like Microsoft Authenticator or Google Authenticator. These generate codes without internet.
Avoid SMS for high-value accounts if possible. SMS can be intercepted. Use an app or security key instead.
Save backup codes in a secure location in case you lose your phone.
Never approve an MFA prompt you did not initiate. Deny it and report it immediately.
Enroll MFA on all critical accounts: email, EHR, banking, accounting, and any system with sensitive data.

Step 4: Audit Your Passwords

Once your password manager is set up, audit your existing passwords:

Identify reused passwords and replace each with a unique, generated password.
Identify weak passwords and replace with strong passphrases or generated passwords.
Update passwords for breached accounts. If you hear about a breach at a service you use, change that password immediately.
Remove passwords from sticky notes and browser autofill. Store everything in the password manager.

This guide is a supplement to Module 02: Password Hygiene and MFA. Complete the full module for interactive training and knowledge checks.

Go to Module 02