Password Hygiene & MFA

MODULE 02 / FOUNDATIONAL10 min / Includes knowledge checks and quiz

Password Hygiene & MFA

Passwords are the keys to your organization’s data. Learn how to create strong passwords, use password managers, and leverage MFA to stop attackers even when passwords are stolen.

A person at a clean modern desk setting up a password manager on their laptop

What You Will Learn

Passwords are the keys to your organization’s data. This module covers how to create strong passwords, why password managers are essential, and how multi-factor authentication (MFA) stops attackers even when passwords are stolen.

  • Password fundamentals: what makes a password strong or weak
  • Password managers: why you should use one and how they work
  • Multi-factor authentication (MFA): the single most effective security control
  • Common password mistakes: habits that put your organization at risk
  • Passphrases: a better way to create passwords you can actually remember

Why Passwords Matter

Weak passwords are one of the easiest ways for attackers to break into your accounts. When an attacker gets your password, they can access your email, your files, your patient records, your client data, and your financial systems. From one compromised account, they can often reach others.

The challenge is that you likely have dozens of accounts, each needing a password. No one can remember that many strong, unique passwords. That is where password managers and MFA come in.

Quick Check

Which of these passwords is the strongest?

A) Summer2026!
B) P@ssw0rd123
C) correct-horse-battery-staple-orchid
D) YourName2026

What Makes a Password Strong

Strong Password Checklist

  • Length over complexity. A 16+ character password is stronger than an 8-character password with symbols. Every additional character makes cracking exponentially harder.
  • Unique for every account. Never reuse passwords. If one account is breached, attackers will try that password on every other account.
  • No personal information. Avoid names, birthdays, pet names, and company names. These are easy to find on social media.
  • Use passphrases. Combine 4-5 random words like purple-elephant-window-festival. They are long, strong, and memorable.
  • No patterns. Avoid keyboard patterns (qwerty, 12345678) and seasonal passwords (Summer2026, Spring2026).

Password Managers: Your Security Vault

A password manager is a tool that generates, stores, and auto-fills strong, unique passwords for every account. You only need to remember one master password. The password manager handles the rest.

STM recommends and can deploy password managers for your organization. Popular options include Bitwarden, 1Password, and LastPass. They work across all your devices and browsers.

Quick Check

Your colleague says they use the same password for their email and their EHR login because it is easier. What should you tell them?

A) That is fine as long as the password is strong
B) Reusing passwords is dangerous. If one account is breached, attackers will try that password on every other account
C) It is okay if they change it once a year
D) It is fine as long as they do not write it down

Multi-Factor Authentication (MFA)

MFA requires two forms of verification to log in: something you know (your password) and something you have (your phone, an app, or a security key). Even if an attacker steals your password, they cannot log in without the second factor.

MFA is the single most effective security control you can implement. Microsoft reports that MFA blocks over 99% of automated account attacks. If you implement only one security measure from this training, make it MFA.

Types of MFA

  • Authenticator app (recommended): Apps like Microsoft Authenticator or Google Authenticator generate a 6-digit code that refreshes every 30 seconds. No internet connection needed.
  • Text message (SMS): A code is texted to your phone. Less secure than an app because SMS can be intercepted, but better than no MFA.
  • Security key (most secure): A physical USB device like a YubiKey that you tap to verify. Nearly impossible to phish.
  • Push notification: Your phone shows a prompt asking you to approve or deny the login. Fast and easy, but only approve prompts you initiated.

Quick Check

You receive an MFA push notification on your phone asking you to approve a login, but you are not trying to log in to anything. What should you do?

A) Approve it to make the notification go away
B) Deny it and report it to IT immediately. Someone may have your password.
C) Ignore it and wait for it to expire
D) Approve it and then change your password later

Common Password Mistakes to Avoid

Password Mistakes That Put You at Risk

  • Reusing passwords across accounts. If one is stolen, all are compromised.
  • Writing passwords on sticky notes. Especially on your monitor where anyone can see them.
  • Sharing passwords with colleagues. Every person should have their own account. Shared accounts make it impossible to track who did what.
  • Using personal passwords for work accounts. If your personal account is breached, your work accounts are too.
  • Never changing passwords after a breach. If you hear about a breach at a service you use, change that password immediately.

How This Looks in Your Industry

Healthcare Practices

EHR systems, patient portals, and billing platforms all require passwords. HIPAA requires unique user IDs and passwords for each person. Shared passwords violate HIPAA because you cannot track who accessed patient records. MFA on your EHR is one of the strongest HIPAA safeguards.

Legal Firms

Case management systems and client portals contain privileged information. Shared passwords can waive attorney-client privilege by making it impossible to prove who accessed what. MFA on email is essential because email is the primary communication channel for client matters.

Nonprofits

Donor databases, grant portals, and accounting systems contain sensitive financial and personal data. Password managers are affordable (some are free for small teams) and dramatically improve security without adding burden to volunteers.

Daycares and Schools

Student information systems, parent communication apps, and state reporting portals require strong access controls. COPPA and FERPA require reasonable security measures. MFA on staff accounts is a simple, effective way to meet those requirements.

Key Takeaways

  • Use passphrases: 4-5 random words are stronger and easier to remember than short complex passwords.
  • Never reuse passwords. Every account gets a unique password. A password manager makes this easy.
  • MFA blocks over 99% of automated account attacks. It is the single most effective security control.
  • Never approve an MFA prompt you did not initiate. Deny it and report it immediately.
  • Password managers generate, store, and auto-fill strong passwords. You only remember one master password.

Module Quiz

Complete this quiz to test your understanding of the module. Answers are provided below each question.

1. What is the main benefit of using a password manager?

A) It remembers your passwords so you never have to type them
B) It generates strong unique passwords for every account and you only remember one master password
C) It makes your passwords visible to IT staff
D) It speeds up your computer

2. MFA blocks what percentage of automated account attacks according to Microsoft?

A) About 50%
B) About 75%
C) Over 99%
D) 100%

3. You want to create a strong password you can actually remember. Which approach is best?

A) Use your pet’s name plus your birth year
B) Use a short password with lots of special characters like P@$$w0rd!
C) Use a passphrase: 4-5 random words like river-cloud-pencil-thunder-window
D) Use the same strong password for everything so you only remember one

4. A colleague asks to borrow your EHR login because theirs is not working. What should you do?

A) Share it just this once to help them out
B) Refuse and direct them to IT or admin to reset their password
C) Share it but change it afterward
D) Share it and watch them use it

5. Which type of MFA is most secure?

A) SMS text message codes
B) Email verification codes
C) A physical security key like a YubiKey
D) A phone call verification

Module 02 of 10 – Cybersecurity Essentials Training

Previous ModuleBack to ResourcesNext Module