We're Moving From Passwords to Longer Passphrases
Health care systems are being targeted by cybercriminals, so it’s important that we have safeguards in place for our network and the data stored within it.
With that in mind, we are updating our password security policy to require 15-character passphrases instead of passwords when you update your AD credentials (the username and password you use to log in to email, Epic and other Carilion applications) after Wednesday, Dec. 1. Because passphrases are more secure than passwords, you will only need to update your passphrase once per year (rather than the current 90 days).
Historically, “password complexity” meant long strings of numbers, characters and symbols that were nearly impossible to remember. A passphrase is a sequence of words or text, such as a short sentence or a group of random words, that may contain spaces and special characters. Passphrases are easier to remember and are more secure because of their length.
Here are a few examples:
- Time for a strong coffee!
- Hike Carvins Cove
- Lost snail crawl beach.
You can keep using your current password for now. If you update your log-in information prior to Dec. 1, you can continue to use the current password criteria, although we recommend changing to a passphrase because it is more secure. After Dec. 1, you will need to choose a passphrase the next time you update your log-in information. Your passphrase will then not need to be changed for an entire year!
If you have questions, contact Rob Mireles, Information Security, at rmireles@carilionclinic.org.
The next time you update your AD password after Dec. 1, you'll be asked for a longer passphrase instead of a password.
Passphrases are easier to remember and harder for cybercriminals to crack.
Because they are more secure, you will only need to update your passphrase once a year!