Password and MFA Policy for Temporary Traveling Nurses on Short Assignments
Strong Password Requirements
Baseline standard
You must create a unique password for every system you access. Use at least 14 characters, or a multi‑word passphrase of 4 or more unrelated words totaling 16+ characters. Avoid names, dates, facility terms, or predictable patterns.
- If not using a passphrase, include three of these: uppercase, lowercase, number, symbol.
- Blocklisted and previously breached passwords are rejected.
- Passwords must not be shared, emailed, texted, or stored in unsecured notes.
Creation and storage
Generate and store passwords in the approved password manager. Do not save credentials in unmanaged browsers or personal notes. Systems store passwords only as salted, slow‑hash values (for example, Argon2id, bcrypt, or PBKDF2) to protect them at rest.
Rotation, reuse, and resets
Routine time‑based changes are not required unless risk is detected. Change your password immediately after suspected compromise or policy violation. Reuse of the last 24 passwords is prohibited, and minimum password age prevents rapid cycling.
Self‑service resets require successful MFA. Help‑desk resets demand identity verification and are recorded in Audit Trail Documentation. All temporary accounts automatically expire at assignment end; see Temporary Account Deactivation in Access Restriction Protocols.
Good passphrase practices
Combine several unrelated words with separators and optional numbers to improve length and memorability. Do not base phrases on song lyrics, quotes, clinical terms, or personal information that others can guess.
Multi-Factor Authentication Implementation
Enrollment and supported factors
You enroll in MFA during pre‑boarding so access is ready on day one. Supported factors include an authenticator app that generates a time‑based One-Time Password, push verification on managed devices, FIDO2 security keys, and Biometric Authentication to unlock the device or authenticator.
Backup codes are issued for emergencies and must be stored securely. SMS is used only as a temporary fallback when stronger factors are unavailable.
Where and when MFA is enforced
MFA is required for VPN, EHR/eMAR, email, and all cloud portals. Step‑up prompts appear for high‑risk actions such as remote EHR access, exporting PHI, or signing medication orders. New devices and unusual locations always trigger MFA.
Loss, change, or failure of factors
If a device or factor is lost, contact the service desk immediately. A short, tightly verified bypass may be granted, and the event is captured in Audit Trail Documentation. Suspicious factor changes invoke Security Incident Response with containment and re‑enrollment.
Usability and privacy safeguards
Offline codes from authenticator apps and hardware keys support low‑connectivity environments. Biometrics never leave the device; they gate access to factors and do not replace MFA where two independent factors are required.
Access Restriction Protocols
Role and attribute controls
Access follows least‑privilege principles using role‑based and attribute‑based Access Control Policies. Your permissions reflect unit, shift, and job function; elevated rights require manager approval and time‑boxed justification.
Time‑bound access and Temporary Account Deactivation
Accounts are provisioned with start and end dates aligned to your assignment. Temporary Account Deactivation occurs automatically within 24 hours of assignment completion, with early revocation if you depart sooner or become inactive.
Session and location safeguards
Idle sessions lock after 15 minutes and terminate after 8 hours. Concurrent logins are limited, and re‑authentication is required for sensitive actions. Access from unmanaged or noncompliant devices is blocked; VPN and geo/risk checks reduce off‑site exposure.
Just‑in‑time privileges
When higher access is required (for example, float support), privileges are granted just‑in‑time for a short window with step‑up MFA and automatic rollback. All changes are recorded for review.
Security Training Delivery
Pre‑boarding and day‑one essentials
Before your first shift, you complete a concise module covering password hygiene, MFA use, phishing awareness, and Access Control Policies. A short assessment and acknowledgement confirm comprehension.
On‑shift reinforcement
Micro‑lessons appear in context (for example, before first VPN use) and are available offline. Quick‑reference guides explain what to do if a device is lost, an email looks suspicious, or MFA fails.
Measurement and accountability
Completion is tracked, with reminders for overdue items. Phishing simulations and spot checks validate effectiveness. Results inform targeted refreshers during longer placements.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Device Usage Guidelines
Managed and BYOD standards
Use a managed device when provided. If BYOD is allowed, enroll in mobile device management before access. Devices must have full‑disk encryption, automatic locking, current OS patches, and no jailbreaking or rooting.
- Enable screen lock (auto‑lock ≤ 5 minutes) and secure unlock (strong PIN or password).
- Run approved EDR/antimalware and keep definitions current.
- Follow Data Encryption Standards for storage and backup on managed endpoints.
App use and data handling
Use only approved apps for EHR, messaging, and file access. Disable unapproved cloud sync and clipboard sharing for PHI. Local caches auto‑purge and cannot be copied to personal storage or messaging apps.
Network and remote access
Prefer hospital Wi‑Fi; use VPN when off‑site. Avoid public Wi‑Fi and open hotspots. Tethering requires VPN and adheres to the same data‑handling restrictions as on‑premise access.
Lost, stolen, or compromised devices
Report immediately for remote lock/wipe and credential revocation. A Security Incident Response ticket is opened, MFA seeds are replaced, and activity is reviewed for potential exposure.
Removable media
Removable media is disabled by default. If clinically required, only organization‑issued, hardware‑encrypted media may be used, with content scanning and checkout logs.
Compliance Monitoring Procedures
Audit Trail Documentation
All access, MFA events, EHR reads/changes, downloads, print actions, and admin operations are logged with user, device, time, and source. Clock synchronization ensures accurate sequencing across systems.
Continuous monitoring and alerts
Logs feed a SIEM to detect anomalies such as impossible travel, repeated MFA failures, unusual after‑hours access, or bulk record views. DLP and EDR signals provide additional context for rapid containment.
Periodic reviews and attestations
Supervisors review access monthly and at assignment close‑out. Exceptions trigger immediate remediation. Deprovisioning is verified, and sampling checks confirm that Temporary Account Deactivation occurred as scheduled.
Incident management lifecycle
Suspected misuse initiates Security Incident Response: triage, contain, eradicate, recover, and document. Post‑incident reviews drive control improvements and targeted training.
Data Protection Measures
Encryption in transit and at rest
Use TLS 1.2+ (preferably TLS 1.3) for all network traffic. Apply AES‑256 or equivalent for stored data, aligning with organizational Data Encryption Standards and regulatory obligations.
Key management
Keys reside in centralized, access‑controlled modules with rotation, backup, and separation of duties. All key activities are logged and periodically audited.
Data minimization and retention
Collect only the minimum PHI needed for care. Temporary caches auto‑expire, and retention schedules purge data when no longer required. Secure disposal techniques prevent recovery.
Resilience and recovery
Backups are encrypted, tested, and protected against tampering. Recovery objectives support clinical continuity, and restoration activities are recorded for Audit Trail Documentation.
Together, strong passwords, robust MFA, least‑privilege access, vigilant monitoring, and disciplined data protection keep patient information secure while you deliver care on short assignments.
FAQs
What password complexity requirements should temporary nurses follow?
Use a unique password of at least 14 characters, or a 16+ character multi‑word passphrase. If not using a passphrase, include three of four types: uppercase, lowercase, number, symbol. Reuse is prohibited, high‑risk passwords are blocked, and resets require MFA.
How is MFA implemented for traveling nurses?
MFA is enrolled during pre‑boarding and enforced for VPN, EHR/eMAR, email, and cloud apps. Supported methods include authenticator app One-Time Passwords, push on managed devices, FIDO2 security keys, and Biometric Authentication for device unlock. Backup codes are provided for emergencies.
How are temporary accounts managed after assignments?
Accounts are created with start/end dates and the least privileges needed. Temporary Account Deactivation occurs automatically within 24 hours of assignment completion, with early revocation for departures or inactivity. All changes are captured in Audit Trail Documentation.
What training is provided on security policies?
You complete a concise pre‑boarding module on passwords, MFA, phishing, Access Control Policies, and data handling, followed by acknowledgements. On‑shift micro‑lessons and simulations reinforce behaviors, and results guide targeted refreshers during longer placements.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.