Do You Still Need to Change Your Password Every 90 Days? What NIST Now Says for Santa Clarita Practices

The reset email goes out on the first Monday of the quarter. By lunchtime half the office has moved from Spring2026! to Summer2026!, one person has written the new one on the back of a business card in the top drawer, and the practice has recorded another completed security control. Everybody did what they were told.

Here is the part nobody mentions at the staff meeting. The federal guidance most American password policy traces back to now tells the systems that check your password not to require a periodic change at all, and HIPAA never named an interval in the first place. The habit outlived the reason, and it is quietly making the passwords in your office worse.

Overview

Start with the document rather than the argument. NIST SP 800-63B is the federal digital identity guideline that most password policy in American business can be traced back to, and its current text is unambiguous. In section 3.1.1.2 it states that verifiers and credential service providers shall not require subscribers to change passwords periodically, and that they shall force a change only where there is evidence the authenticator has been compromised. In the same section it states that they shall not impose composition rules, meaning the mandatory mixture of upper case, digit and symbol that your login screen still demands.


Those are requirements on the systems that verify passwords rather than on your office directly. The practical translation for a practice in Valencia or Newhall is simple enough: the two rules your staff experience most often, the quarterly reset and the character mixture, are the two the standard now tells software not to enforce.


The second surprise is what HIPAA actually says, because most offices believe the 90 days came from there. It did not. The Security Rule's password management item at 45 CFR 164.308(a)(5)(ii)(D) reads, in full, procedures for creating, changing and safeguarding passwords. It is addressable rather than required, and it names no interval, no length and no character rule. Every number your practice enforces was chosen by somebody, and it is worth knowing who.

The Challenge

Rotation makes passwords worse, which is why the guidance reversed. People do not respond to a forced change by inventing a new strong secret four times a year. They respond by finding a pattern that survives the change, which is how an office ends up with a column of passwords that differ by one character and a season. The attacker who has last quarter's password does not need a cracking rig to guess this quarter's. Microsoft reached the same conclusion for its own products and now recommends in its Microsoft 365 administrator documentation that passwords for cloud accounts be set never to expire, noting that length requirements, special character requirements and change requirements all push passwords toward predictable shapes.


The length numbers are higher than almost any office is running. The same NIST section requires that a password used as a single authentication factor be a minimum of 15 characters. One used as part of multi factor authentication may be as short as 8, and verifiers should permit at least 64. Read that as the trade it is: if a password is the only thing standing between a stranger and the record, it has to be long, and if you would rather keep it short, you owe the account a second factor. Most practices are running eight characters with no second factor, which is the one combination the standard does not contemplate.


What replaced rotation is screening, not scheduling. Verifiers shall compare a proposed password against a blocklist of commonly used, expected or compromised values. That is the control doing the real work now: the weak choice is refused at the moment somebody types it rather than cycled on a calendar. Two more rules in the same section are worth reading aloud to whoever configures your systems. Password hints that an unauthenticated visitor can reach are prohibited, and prompting for security questions, the mother's maiden name and the first pet, is prohibited as well. Those answers are researchable, which our piece on why MFA alone is no longer enough traces into the account recovery flows attackers actually use.


One carve out survives, and it is narrow. If your practice takes card payments, the Payment Card Industry standard is separate from NIST and still carries an interval. Requirement 8.3.9 of PCI DSS version 4.0.1 says that where a password is the only authentication factor for user access, it is either changed at least once every 90 days, or the security posture of accounts is dynamically analyzed with access determined in real time. The applicability note is the part that matters to a small office: the requirement does not apply to system components where multi factor authentication is used. So the rule that forces rotation on you disappears the moment you add the second factor you should be adding anyway.


So why is the reset still running in Saugus and Canyon Country? Because it is visible, cheap and auditable. A rotation interval produces a log, a policy line and a box that ticks, and it asks nothing of the practice except everyone's patience. Screening against compromised passwords, deploying a password manager and turning on multi factor authentication each take a decision, a small budget and an afternoon. The 90 day reset persists because it looks like security spend without being any, which is the same economics our piece on why technology alone is not enough keeps running into.

Why It Matters

You are spending real goodwill on a control that is working against you. Every quarterly reset costs staff time, help desk calls and a measure of patience you will need later when you ask the same people to do something that genuinely matters. Spending that credit on a practice the guidance now advises against is worse than doing nothing.


The written policy is the artifact, not the habit. Under HIPAA the password item is addressable, which means the defensible position is a decision you assessed and recorded, not a number you inherited. A practice that has written down what it does, why, and what it does instead of rotation is in better shape at audit than one running 90 days because the template said so and nobody can say who wrote the template.


The insurance application is going to ask, in its own words. Questionnaires ask about password policy, multi factor coverage and credential controls, and those answers are representations rather than opinions, which is the whole argument of our piece on the audit you already signed. Answering yes to a strong password policy on the strength of a quarterly reset, while eight character passwords with no second factor protect the records, is the kind of answer that is examined after a claim rather than before.

What Organizations Should Watch For

  • Passwords that differ by a season or a digit. Ask one trusted person what the pattern in your office is. There is always a pattern, and knowing it is the fastest honest measure of what rotation has actually produced.
  • Eight character minimums with no second factor. This is the combination the standard specifically does not allow for. Either the password gets much longer or the account gets multi factor authentication.
  • Security questions still guarding account recovery. Mother's maiden name and first pet are prohibited by the current guidance for good reason, and recovery is where accounts are actually taken.
  • Shared logins for the front desk, the scanner or the practice management system. A shared password cannot be rotated meaningfully, cannot be attributed to a person, and quietly outlives every staff change, which is the mechanism our piece on offboarding as a security event lays out.
  • Written passwords in the places everyone knows about. The drawer, the monitor, the shared note. These are the direct output of a rotation policy plus a length requirement with no password manager underneath.
  • A policy document nobody can produce. If the practice cannot show what its password standard is and who set it, then the standard is whatever each system happened to ship with.

Recommended Actions

  • Turn off scheduled expiration where you control it, and write down why. One paragraph citing the guidance and your own assessment converts an inherited habit into a documented decision, which is what addressable actually asks for.
  • Raise the length floor before you touch anything else. Fifteen characters where a password stands alone, and encourage passphrases, which are easier to remember and longer than anything a composition rule produces.
  • Turn on compromised password screening. Microsoft Entra Password Protection covers this for Microsoft 365 tenants, and most identity platforms have an equivalent. This is the control that replaces rotation rather than sitting beside it.
  • Put multi factor authentication on everything reachable from outside the building. Email first, then remote access, then the practice management system. It also removes the PCI rotation requirement for the accounts it covers.
  • Buy the practice a password manager. Long unique passwords are impossible without one, and the drawer full of business cards is the alternative you already have.
  • Keep one trigger for forcing a change. Evidence of compromise, which is the only reason the standard still endorses, and make sure somebody in the office knows they are allowed to pull that lever without asking permission first.

The SecureLynx Perspective

Observe:

In medical practices, accounting firms and law offices around the Santa Clarita Valley, the password conversation is usually the shortest one we have, because the practice already believes it is handled. The reset is running, so the box is ticked. What the walk finds is a season and a year on most accounts, a shared login somewhere important, security questions still guarding recovery, and no screening against compromised passwords anywhere. None of that is negligence. It is a policy written in 2014 still running in 2026.


Adapt:

The work is an afternoon and mostly consists of turning things off. Expiration off where it is under your control, length up, compromised password screening on, multi factor authentication extended to everything facing the internet, a password manager issued, and the shared logins broken into named accounts. That is ordinary identity and account administration rather than a project, sitting on the access control and logging work we would be doing regardless, with the decision itself recorded in the compliance file where an auditor will look for it and exportable from the client portal with the primary copy yours.


Protect:

Two honest limits. Where a system is old enough that it cannot do length, screening or a second factor, the answer is not to pretend, it is to isolate the system and know what you are carrying, which is the same argument our piece on the machine you cannot replace makes about equipment nobody is allowed to touch. And if a specific contract, payer or card brand obliges you to rotate, then you rotate, and we will say so rather than tell you the standard overrides your paper. What we will not do is leave a 2014 policy running because removing it is harder to explain than keeping it. Our pricing is published and the agreements are readable before you ever call.

Common questions

Does HIPAA require changing passwords every 90 days?

No. The Security Rule contains no interval at all. What it has is an addressable implementation specification under the security awareness and training standard, calling for procedures for creating, changing and safeguarding passwords. Addressable means you assess whether it is reasonable and appropriate for your practice, implement it or document an equivalent alternative, and record the reasoning either way. It does not mean optional and it does not mean 90 days. The number almost certainly reached your office through an old policy template, a vendor default, or an auditor repeating a convention, and none of those are the rule. If you keep a rotation interval, keep it because you decided it fits your environment, and write down why.

What is the current NIST password guidance?

NIST SP 800-63B sets requirements on the systems that verify passwords. Verifiers shall not require subscribers to change passwords periodically, and shall force a change only where there is evidence the authenticator has been compromised. Verifiers shall not impose composition rules such as requiring mixtures of character types. A password used as a single authentication factor shall be a minimum of 15 characters, while one used as part of multi factor authentication may be as short as 8, and verifiers should permit at least 64. Verifiers shall compare a proposed password against a blocklist of commonly used, expected or compromised values. Password hints accessible to an unauthenticated visitor are prohibited, and so is prompting for security questions.

If we stop expiring passwords, what do we do instead?

Three things carry the weight that rotation was pretending to carry. Screen new passwords against a list of known compromised values, so the weak choice is refused at the moment it is made rather than reset on a schedule. Put multi factor authentication on everything that faces the internet, because a stolen password with a second factor behind it buys an attacker much less. And give people a password manager so long unique passwords are possible at all, since the practical reason staff reuse a password across systems is that remembering a dozen good ones is not a human skill. Then force a change when you have evidence of compromise, which is the one trigger the standard still endorses.