Saved · this browser
Chapter 3 · §164.308(a)(5)(ii)(D) / §164.312(d)

Your Passwords

A password you reused on some recipe forum can open your EHR. If that forum gets hacked and you used the same password for work, whoever grabs the leaked list can try it on your accounts — and that’s the most common way an everyday breach turns into a healthcare one. Two simple tools shut that door: a password manager, and a second step at login — a texted code or a quick tap in an app. And if losing your phone is the worry: when you set that second step up you get a set of backup codes — save those, and a lost or broken phone never locks you out of your own records.

The newer logins have the same safety net. A passkey — the face- or fingerprint-style sign-in that’s starting to replace passwords — isn’t trapped on one device; it syncs across the devices you own, and you can always set up a new one or fall back to those backup codes if a device breaks. A password managerhands you a one-time recovery key the day you set it up — keep it somewhere safe and you can sign back into your vault from any device. None of these is a door that locks behind you with no spare key.

Why this chapter exists, in plain English

Picture this: your laptop isn’t stolen, your office isn’t broken into, and nothing on your end looks wrong. A year ago, a recipe-forum website you’d almost forgotten about was breached — the password list leaked onto the internet. This morning, someone runs that list against your EHR. The email matches yours. So does the password. The EHR just opened. Nothing was stolen from you. Nothing on your laptop mattered. The password was the whole attack.

HIPAA’s rule on this gets short once you cut the legal wording: use good passwords, and make sure only you can log in. That’s really all it asks. Everything below is just the easy way to do both — you don’t have to know the rule, only do the two things.

Two tools carry this chapter. A password manager remembers a different strong password for every account, so one leaked password can’t open the rest. And a second step after your password — a code texted to your phone, or a quick tap in an app — means that even if a password does leak, no one can get in without your phone too. Both are free or close to it, and each takes under an hour to set up.

01

Setup

Which of these accounts touch anything client-related? Pick every one.

Don’t worry about being exhaustive on the first pass — you can come back and add accounts as you remember them.

03

Where you stand

Not quite there yet

Pick at least one account above to begin.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.