Theyre difficult to memorize so employees skirt hospital IT rules when conjuring them up anyway, group says.The National Institute of Standards and Technology on Wednesday published new guidance on how to strengthen passwords. Why now? Research shows that the de facto standard practice of requiring users to include a mix of uppercase and lowercase letters, numbers and at least one symbol, is more trouble than its worth.Analyses of breached password databases reveal that the benefit of such rules is not nearly as significant as initially thought, NIST explained. The impact on usability and memorability is severe.

