TL;DR: A hospital password audit found over 90% of credentials could be cracked with a simple hybrid dictionary attack, but the deeper issue was governance fit: the strongest security practice still failed to reflect clinical urgency and operational reality, according to SailPoint. The lesson is that identity controls must match how people actually work, not just how policies are written.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “Facepalm Files: To password or not to password, a healthcare cybersecurity tale”.
Key questions
Q: How should hospitals balance strong password policies with clinician workflow efficiency?
A: Hospitals should treat password strength and workflow efficiency as a single design problem, not competing goals.
Q: Why do standard password policies often fail in hospitals?
A: Because they assume compliance equals security and that users have time to enter complex credentials under pressure.
Q: What are the signs that human authentication controls are too rigid?
A: Common signs include repeated bypass requests, staff using memorable patterns despite policy, and exceptions that never get retired.
Practitioner guidance
- Assess workflow-fit authentication Review whether current login controls match the time pressure and interruption patterns of clinical work, especially for emergency care and shift-based access.
- Test passwords against offline cracking Measure the actual crackability of stored password hashes with realistic hybrid dictionary attacks rather than relying on composition rules alone.
- Define emergency access paths Create a separate access path for urgent clinical use so high-friction authentication does not push staff toward unsafe workarounds.
Bottom line: The article shows that a password can satisfy policy and still be easy to crack in practice.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Context is the deciding factor in human authentication. A password policy can be technically sound and still operationally wrong if it ignores how the identity is used. Healthcare is a clear example because urgency, clinical interruption, and shared work patterns change what “usable security” means. The practitioner lesson is that authentication policy has to be judged against the workflow it governs, not against generic enterprise norms.
A few things that frame the scale:
- 55% of healthcare data breaches now originate from a third-party vendor, according to Ponemon Institute’s 2023 Third-Party Risk in Healthcare report.
A question worth separating out:
Q: What should IAM teams prioritise after passwordless becomes the default direction?
A: Prioritise recovery design, interoperability standards, and lifecycle governance. Passwordless changes the authentication surface, but it does not remove identity lifecycle risk. Teams that succeed will treat authentication as one part of a broader trust system covering enrolment, reauthentication, recovery, and revocation across the full user journey.
👉 Read our full editorial: Healthcare password risk shows why best practices need context