Let’s talk about the sticky note on your monitor. You know the one. It’s got your password on it, half the ink rubbed off from where your sleeve brushes it every morning.
You’re not the only one doing this. Walk through any clinic, any billing office, any nurses’ station, and you’ll find passwords living in the open. Taped under keyboards. Stuck to the side of a monitor. Written on a notepad next to the phone. One office I heard about had the Wi-Fi password laminated and mounted on the wall like a piece of art.
Here’s the problem. HIPAA doesn’t care how strong your password is if anyone who walks by your desk can just read it off a sticky note. A 16-character password with symbols and numbers is worthless the second you write it down where a visitor, a vendor, a cleaning crew, or a nosy coworker can see it. You didn’t secure anything. You just moved the lock and left the key next to it.
If you’ve ever taped a password to the bottom of your keyboard, I want you to know this: everyone knows that trick. It’s not hidden. It’s not clever. It’s the first place anyone looks, because everyone has done it or seen someone else do it. IT support checks under keyboards before they check anywhere else. So does anyone with bad intentions.
Think about what’s actually at stake. A password taped under a keyboard at a medical office isn’t guarding your Netflix account. It’s guarding patient records: diagnoses, social security numbers, insurance details, mental health notes, treatment histories. That’s exactly the kind of information HIPAA exists to protect, and it’s exactly the kind of information identity thieves want. One sticky note can undo every other safeguard your organization has in place.
Now let’s talk about BitLocker specifically, because this one comes up more than people think.
BitLocker encrypts the hard drive on your laptop. If the laptop gets lost or stolen, that encryption is what stands between a stranger and everything on that machine, including any patient data that’s stored or cached locally. The whole point of BitLocker is that even if someone physically has your laptop, they can’t get into it without the password or recovery key.
So here’s the part that should make you wince: taping the BitLocker password to the laptop itself defeats the entire purpose. If the laptop is stolen, the password goes with it. You’ve built a locked door and hung the key on the doorknob. The thief doesn’t need to be a hacker. They just need eyes.
This happens more than people admit. A laptop gets left in a car, a bag gets grabbed at the airport, a device walks out of an unlocked office. If the recovery key is sitting on a sticky note in the laptop bag or taped to the case, the encryption did nothing. Zero protection. All that setup, all that IT work, undone by a piece of paper.
None of this means you need to memorize forty different passwords or live in fear of forgetting your login. There are real solutions that actually work:
Use a password manager. Your organization likely has one approved for use, or can point you to one. You remember one master password, and the manager remembers the rest. This is the single biggest upgrade you can make, and it takes less effort than maintaining a drawer full of sticky notes.
Store recovery keys the way IT tells you to. Most organizations back up BitLocker recovery keys to a secure, centralized location, like Active Directory or a dedicated key management system. If you’re not sure where your recovery key lives, ask your IT team. Don’t improvise a solution with a Sharpie.
Lock your screen every time you step away. Windows key + L takes one second. If your password is memorized instead of written down, and your screen locks automatically, you’ve closed off two of the easiest ways someone gets into your system.
Report it if you spot it. If you see a sticky note with a password on a coworker’s desk, say something. Not to get anyone in trouble, but because it’s a five-second fix that prevents a real problem. Most people just haven’t thought it through. A quick heads-up usually does the trick.
Passwords are only useful when they’re actually private. The second you write one down somewhere visible, you’ve handed over the one thing standing between patient data and anyone who walks by. Use a password manager. Trust your IT team’s process for recovery keys. Lock your screen. And retire the sticky note.
Your future self, and every patient whose information you’re protecting, will thank you.