Password Policy
Purpose
To establish a standard for creation of strong passwords, the protection of those passwords, and the frequency for changing those passwords.
Policy
- Password construction
- All passwords must conform to this policy.
- Users must not use the same password across all accounts.
- Users must not use the same password for iEHR accounts as personal accounts.
- Each user’s password should meet the minimum requirements as outlined below:
- Must be a minimum of eight characters in length.
- Must contain a unique character.
- Must contain a number.
- May not contain your username or any part of your full name
- Passwords must not include easily guessed information such as personal information, names, pets, birth dates, etc.
- Passphrases are better used than passwords.
- Password change
- All passwords will be changed every 90 days.
- If a password is compromised, the Security Officer will be notified and the password will be changed immediately.
- Users may not reuse the last five passwords.
- Password protection
- Passwords must not be shared with anyone.
- Do not write down passwords and do not post them anywhere.
- Do not store passwords in documents that are not encrypted.
- Do not use the “remember password” feature on applications.
- Do not send passwords through email.
- Do not reveal passwords over the phone.
Violations
Any individual, found to have violated this policy, may be subject to disciplinary action up to and including termination of employment.