Your Biggest Risk Is a Reused Password
Security programs often emphasize sophisticated attacks. Many practice breaches still begin with valid credentials used by the wrong person.
CareScope Editorial/September 7, 2026/3 min read

The short version
- Most incidents in small and midsize practices begin with valid credentials, not malware.
- Multi-factor authentication on email and remote access closes the majority of that path.
- Offboarding delays and shared logins are the two gaps auditors find most often.
Why it matters
Security spending in practices tends to follow the scariest headline, which means money goes toward defending against attacks that are rare while the common path stays open. Credential-based intrusion is boring, cheap for the attacker, and by far the most likely way your organization ends up on a notification list.
Why credentials keep winning
An attacker with a working username and password does not need to break anything. They log in. Detection tools that look for malicious software see nothing unusual, because nothing unusual is happening — except that the person typing is not your billing manager.
The supply of credentials is effectively unlimited. Reused passwords surface in unrelated breaches constantly, and healthcare staff, like everyone else, reuse them.
The four things that actually close the gap
- Multi-factor authentication on email, remote access, and the EHR. Email first, because it is the reset path for everything else.
- Named accounts with no sharing, including at the front desk. Shared logins make it impossible to answer "who did this?" after the fact.
- Same-day offboarding, tied to payroll rather than memory. Access that outlives employment is the single most common finding in a practice review.
- A short list of who has administrative rights, reviewed twice a year. It is usually longer than leadership expects.
What to do about the friction complaint
The objection to MFA is always time. The honest answer is that it costs seconds per login and it is the only control on this list that reliably stops an attacker holding a valid password. Roll it out to email first, give staff a two-week runway, and use app-based codes rather than text messages where the system supports it.
Access control is not a security project. It is an operations habit with a security effect.
The CareScope take
If you do one thing this quarter, turn on multi-factor authentication for email and remote access. If you do two, tie account removal to the payroll process so departures close access the same day.
Ignore anything sold as advanced threat detection until those two are done. Buying detection before you have closed the front door is spending money to watch yourself get breached.
Sources
- Data Breach Investigations Report — Verizon Business
- More Than a Password: Multifactor Authentication — CISA
- NIST SP 800-63B, Digital Identity Guidelines: Authentication and Lifecycle Management — NIST
CareScope cites primary sources — regulators, standards bodies, and published research — wherever a claim depends on them. Reporting is editorially independent and is not legal advice.
identity · access · breach

