Millions of patients possibly at risk due to poor passwords at healthcare orgs – here’s how to stay safe


- NordPass and NordStellar reviewed terabytes of data
- The analysis uncovered poor password practices in the healthcare industry
- Organizations are lacking staff training and strong policies
Hygiene in hospitals and clinics is essential, but cyber-hygiene – despite being equally important – is constantly being neglected, experts have warned.
A report from NordPass and NordStellar has claimed weak password practices are “dangerously common” in the healthcare industry.
Based on a review of 2.5TB of data extracted from various publicly available sources (including the dark web), the two organizations found that different medical institutions, including private clinics and hospital networks, all rely on “predictable, recycled, or default passwords” to protect critical systems. As a result, sensitive patient data, and possibly their health, is placed at immense risk.
Carelessness
“When the systems protecting patient data are guarded by passwords like ‘123456’ or ‘P@ssw0rd,’ that’s a critical failure in cybersecurity hygiene. In a sector where both privacy and uptime are vital, this kind of carelessness can have real consequences,” said Karolis Arbaciauskas, head of business product at NordPass.
The report also lists the most frequently used passwords identified in the healthcare sector. If you’re using any of these (or a variant), make sure to change them for something tougher to crack:
- fabrizio19
- 123456
- Melu3@12345
- @Vow2017
- Mercury9.Venus8
- password
- Marty1508!
- Carlton@1988
- 12345678
- @Vowcomm2018
- papa
- 12345
- Durson@123
- P@ssw0rd
- Simetrica
- Raffin2209!
- Asspain28#
- Smith
- neuro
- default
Policies and training
The teams warn passwords that reflect personal names, simple number patterns, or default configurations, are all prime targets for brute-force and dictionary attacks, in which cybercriminals automate the process, and try out countless combinations until they break in.
To make matters even worse – one break-in is more than enough to wreak havoc, as lateral movement can compromise entire networks, expose sensitive data, and result in different malware and ransomware infections.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The report stresses that healthcare institutions “lack clear password management policies or staff training,” which is why they are recommended to enforce strong password policies, eliminate the use of default or role-specific passwords, use a business-grade password manager, train the staff, and introduce 2FA wherever possible.
You might also like
NordPass and NordStellar reviewed terabytes of data The analysis uncovered poor password practices in the healthcare industry Organizations are lacking staff training and strong policies Hygiene in hospitals and clinics is essential, but cyber-hygiene – despite being equally important – is constantly being neglected, experts have warned. A report from…
Recent Posts
- NYT Wordle today — answer and my hints for game #1479, Monday, July 7
- Playdate Season 2 review: Taria & Como and Black Hole Havoc
- 3 features that would actually make me pay for a Samsung Health subscription for my Galaxy Watch – and one big problem it needs to avoid
- 250-million pixel virtual projector sets world record on 280-meter tall building used as a screen
- TikTok’s ‘ban’ problem could end soon with a new app and a sale
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022