logo
logo
Sign in

HIPAA Password Requirements

avatar
Patrick Smith
HIPAA Password Requirements

There is no further guidance about HIPAA password requirements. The reason why HIPAA is not more specific about passwords is to ensure legislation does not need to be updated every time there is a change in password and security best practices. For example, at the time when HIPAA was initially enacted, passwords consisting of a minimum of 6 letters was a best practice. Today, 6-digit alphanumeric passwords can be cracked using brute force algorithms within minutes.

Further, while passwords are currently ubiquitous and are the primary way accounts are secured, that could well change in the future due to advances in two-factor authentication and biometrics. HIPAA allows for future changes and is deliberately flexible so HIPAA-covered entities and their business associates can develop their own password policies – provided they comply with the Security Rule Standards referenced above.

Consequently, policies should be developed that stipulate how passwords are created, changed, and safeguarded. Policies should also address resetting passwords when it is reasonably believed a password has been compromised, shared with an individual other than the account holder, or in response to a cyberattack. Finally, policies for safeguarding passwords should stipulate saved passwords are encrypted and never stored in plain text.

 

collect
0
avatar
Patrick Smith
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more