July is our annual ACUF campaign for donations to help offset the cost of the board. Please click the link below for more details.
Amazing Charts User Forum Donation Campaign

Goal $650 Dollars - $600 Received
2025 ACUF Annual July Contributions
Help fund this site.
ACUF Donation
Most Recent Posts
A Tale of Woe: Only Partial Backups
by JamesNT - 09/05/2025 3:29 PM
Need suggestions
by ChrisFNP - 08/27/2025 7:25 PM
Merged Charts
by ChrisFNP - 08/20/2025 3:09 PM
no office note but it was billed
by ChrisFNP - 08/15/2025 1:25 PM
Removing a medication
by ChrisFNP - 08/14/2025 9:30 AM
How to get in touch with tech support
by ChrisFNP - 08/08/2025 10:08 AM
Member Spotlight
EyeGuy
EyeGuy
Saratoga Springs, NY
Posts: 121
Joined: April 2008
Newest Members
sne787, Dr. Christine Se, ozonr666, ESMI, It's me
4,597 Registered Users
Previous Thread
Next Thread
Print Thread
Rate Thread
#54314 05/11/2013 5:30 PM
Joined: Jun 2010
Posts: 147
rsag Offline OP
Member
OP Offline
Member
Joined: Jun 2010
Posts: 147
It has been suggested that I improve the security of my computer work stations.
With regards to individual work stations, for the computer itself, do you [doctor] or the individual staff member at each station assign the unique password that opens the computer?
And similarly- do you [doctor] assign the unique ac passwords for your staff, or do you have each staff member create and maintain their own ac passwords.

Right now, I sort of have access to everything and 'control' all the passwords.
I would appreciate your feedback


Richard
Pediatrician
Orlando, FL
Joined: Apr 2010
Posts: 1,546
Likes: 1
Member
Offline
Member
Joined: Apr 2010
Posts: 1,546
Likes: 1
I let my staff choose their own, but require that they also provide me with it. Thus they can remember it without writing it down, and I can monitor their inboxes, etc.


David Grauman MD
Department of Medicine
Commonwealth Health Center
Saipan, Northern Mariana Islands
Joined: Sep 2003
Posts: 12,899
Likes: 34
Member
Offline
Member
Joined: Sep 2003
Posts: 12,899
Likes: 34
I agree with David, but I do add a twist to it. I used to do it completely that way.

First, I require an 8 letter alphanumeric password with a number that is WITHIN the password.

Second, I make the password so I don't have to go over their passwords making sure they are not birthdays and cats' names. Users will do this; of course, you can change them, but I find the following to be the most secure way.

I assign passwords, and I use a song or nursery rhyme for security and ability to remember. For instance, for one user, I will use:

We all live in a yellow submarine which then translates to:

waL4iaYs

The chances of that being cracked by guessing or brute force would take years. They can remember it, and, more importantly, I can remember it. I do write them all down on the server, encrypted. And, I keep a card in my wallet.

I do not make them change the password every three months or so. The more you make them remember, the more likely they will put a sticky on the back of their computer.

I do make a limit of five tries (three is too easy to reach) before freezing the computer, at which time I can reset the password.

I make them log off if they are leaving their computer, otherwise, they can log off, lock or let the screensaver lock their computer.

It has been drilled into their heads that at no time can anyone give away their password and at no time can a user, use someone else's computer under that user's account. They have their own account. I have written up three users for this. It is a serious offense since a server on a domain can monitor all logins and who logged into what machine at what time.

Summary: I make the passwords using phrases such as Sorry seems to be the hardest word: sstbtH8w. They cannot give them out or use any other person's account in their name.


Bert
Pediatrics
Brewer, Maine

Joined: Sep 2011
Posts: 86
Member
Offline
Member
Joined: Sep 2011
Posts: 86
I assign passwords to most of the staff, though the strength of Bert's passwords put my passwords to shame. We don't have a client-domain setup; we just share certain folders over the network. Some of the folders have sensitive information, so we encrypt those using the windows encryption tool (right click, properties, the advanced button, encrypt).

Another method we employ is having the monitors automatically blackout after a minute of inactivity and the computers go into standby&lock after ~15-45 minutes of inactivity.

For more information about general computer security, I'd suggest looking throughout this. Sandeep and Indy, among others, have some great posts that tackle computer security issues.


Mario
Office Administrator
Pediatrics

Moderated by  ChrisFNP, DocGene, JBS, Wendell365 

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Who's Online Now
0 members (), 20 guests, and 29 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
imcffp 3
Bert 2
JBS 2
joseph 1
Top Posters
Bert 12,899
JBS 2,991
Wendell365 2,367
Sandeep 2,316
ryanjo 2,084
Leslie 2,002
Wayne 1,889
This board is dedicated to the memory of Michael "Indy" Astleford. February 6, 1961 -- April 16, 2019




SiteLock
Powered by UBB.threads™ PHP Forum Software 7.7.5