← Back to blogCompliance

Passwords, Passphrases, and MFA for Clinic Staff

23 July 2026 · 4 min read

Passwords are still the first line of defence on almost every system a clinic runs — the PMS, email, banking, Medicare Online, My Health Record. Get this one basic thing wrong across enough accounts and everything downstream inherits the risk. Drawing on guidance from the Australian Digital Health Agency, here's the practical version of what actually makes a password strong, translated for a clinic team rather than an IT department.

Use a passphrase, not a password

The strongest approach isn't a shorter password with more symbols crammed in — it's a longer passphrase built from unrelated words. Four or more random words, unrelated to you, your work, or your family, with a few numbers or symbols mixed in, is both easier to remember and dramatically harder to crack than something like "Spring2024!". Aim for at least 14 characters.

Never reuse a password across accounts

This is the single most common mistake, and the most damaging one. If one account gets compromised — even a low-stakes one, like an old newsletter signup — and you've reused that password elsewhere, the attacker now has a working key to every other account using it. This is sometimes called the "domino effect," and it's exactly why a breach at some unrelated website can end up compromising a clinic system months later.

Use a password manager if remembering unique passphrases is impractical

Nobody can genuinely remember a unique, strong passphrase for every system they use. A reputable password manager solves this by generating and storing them for you, protected behind one very strong master passphrase. The trade-off: that master passphrase needs to be genuinely strong, because it's now the one key that matters. Never write it down near a device, and enable multi-factor authentication on the password manager itself if it's offered.

Turn on multi-factor authentication everywhere it's available

A password alone is only useful until it's discovered — by a phishing email, a data breach at another company, or simple guessing. Multi-factor authentication (MFA) adds a second check: something you know (your passphrase) plus something you have (a code from your phone, an app, or a token) or something you are (a fingerprint). Even if a password leaks, MFA is usually enough to stop it being used.

Enable it on anything that touches patient data or money — PMS logins, email, banking, and especially any IT administrator accounts.

How attackers actually get in

Understanding the method makes the advice make more sense:

  • Phishing and social engineering — tricking someone into simply handing over their credentials, rather than "hacking" anything technical.
  • Brute force attacks — software trying billions of character combinations per second until one works. Length is the defence here; every extra character multiplies the time required.
  • Dictionary attacks — trying common words, names, and known leaked passwords first. This is why "password123" or a pet's name fails instantly, no matter how confident it feels.

Five habits to embed across the practice

  1. Never share your passphrase with anyone — you can be held responsible for what happens under your login.
  2. Use a different passphrase for every account.
  3. If remembering them is the barrier, use a password manager with a very strong master passphrase.
  4. If you suspect a passphrase has been seen or guessed, change it immediately — don't wait.
  5. Aim for 14+ characters, mixing case, numbers, and symbols.

None of this requires a security budget — just a habit change, and turning on options (MFA, a password manager) that are usually free and already sitting in your existing software.

This article draws on guidance published by the Australian Digital Health Agency.

Not sure where your practice stands?

A Compliance Gap Assessment covers backup and DR posture, access controls, and compliance documentation — a written report with a prioritised roadmap.