HNEDirect Provider Portal Password Policy Update
Posted on November 28, 2017
At Health New England, we are committed to keeping our stakeholders’ personal information confidential and secure. We continually monitor, evaluate and improve our cyber security policies, practices and tools. To better protect everyone, we are changing our password policy in accordance with industry guidelines and best practices.
The password policy update affects users of the HNEDirect Provider Portal and you have been identified as a user of this portal.
We will be rolling out new password requirements in phases during the month of December to be completed by December 31, 2017. During this time, your current password will expire and you will be asked to reset your password according to the new guidelines below.
What you will need to do
At some point during December when you attempt to log into the HNEDirect Provider Portal, you will be alerted that your password has expired and you will be prompted to reset it following these rules:
- Password must be a minimum of 8 characters in length
- Password must contain characters from 3 of the following 4 categories:
- Uppercase alphabetic character
- Lowercase alphabetic character
- Numeric character (0 through 9)
- Special character
- New password cannot be the same as the previous 10 passwords that were used
After this initial reset, you will be asked to change your password every 90 days.
Please note: You cannot reset your password more than once in a 24-hour period.
Tips for choosing a new password:
- Choose a password that is unique to this site. Do not reuse a password you use for another site.
- Don’t use easily guessed passwords, such as “password,” “12345678,” “aaaaaaaa,” etc.
- Do not choose passwords based on details that may not be as confidential as you’d expect, such as your birth date, your Social Security Number or telephone number, or names of family members.
- Do not use words that can be found in the dictionary. Online password-cracking tools often come with dictionary lists that will try thousands of common names and passwords. If you must use dictionary words, try adding a numeral to them, and punctuation at the beginning or end of the word (or both).
- Avoid using simple adjacent keyboard combinations. For example, “qwerty” and “asdzxc” and “123456” are horrible passwords and that are trivial to crack.
- Some of the easiest-to-remember passwords aren’t words at all but collections of words that form a phrase or sentence, perhaps the opening sentence to your favorite novel, or the opening line to a good joke.
If you have any questions about the policy change, please contact Provider Relations at (800) 842-4464, ext. 5000. If you need HNEDirect technical support, call (413) 233-3311 or toll-free at (855) 415-9978.







