Password Requirements
This article explains the password requirements for your Sessions Health account and why we support long, memorable passphrases over strict complexity rules.
Our password requirements are simply that they must be at least 8 characters.
Why Don’t You Require Strong Passwords?
Password guidance has changed significantly in recent years. As explained in this article, modern standards recommend removing unnecessary complexity requirements.
Updated recommendations from the National Institute of Standards and Technology (NIST) encourage the use of long, memorable passphrases rather than complex “strong” passwords. Sessions Health follows these best practices to help keep your account secure and easy to access.
Why We Support Passphrases
Passphrases, which are long strings of words that are easy for you to remember but hard for others to guess, are now considered one of the most effective ways to protect your account. They’re typically more secure than short, complex passwords, and they reduce the frustration that often comes with meeting strict character requirements.
We also allow shorter, traditional strong passwords if that’s your preference.
Why We Don’t Enforce Strict Complexity Rules
Research shows that requiring special characters, numbers, and frequent password changes doesn’t necessarily make accounts safer. In fact, these rules can lead to weaker security because:
- People often choose predictable patterns to meet complexity requirements.
- “Strong” passwords are more likely to be reused across multiple sites, especially without a password manager.
- Reused passwords increase the risk of credential‑stuffing attacks.
- Long, memorable passphrases are harder to crack and easier to maintain.
Even the FBI agrees with this shift, recommending passphrases over complex character requirements.
Examples of Secure Passphrases
Here are a few examples to help you get started:
- IHaveACatNamedSally
- IUsedToLiveInNewYork
- PizzaIsMyFavoriteFood
A good passphrase is long, personal to you, and easy to remember, but difficult for anyone else to guess.