Note
If your organisation uses Single Sign-On (SSO), this password security check does not apply.
To protect your account and data, Nordhealth uses a password security check that detects whether a password has been exposed in a known data breach. If your password is compromised, the system blocks access and requires you to set a new password before you can log in.
How the Password Check Works
Provet integrates with Have I Been Pwned, a trusted service that maintains a database of passwords exposed in data breaches.
When you log in:
Provet hashes your password and sends only the first five characters of the hash to Have I Been Pwned.
Have I Been Pwned compares the hash fragment against known compromised passwords.
If a match is found, Provet blocks the login and displays a message explaining that the password is not safe to use.
This helps prevent attackers from using leaked passwords and known email addresses to gain access to accounts through automated login attempts.
What Happens If Your Password Is Compromised
If the password you enter has appeared in a previous breach:
The system prevents you from logging in.
You must reset your password using the Forgot Password feature on the login page.
You must have access to the email address associated with your account to complete the password reset process.
Note: You will not be able to reuse the same compromised password when resetting it.
If an admin is creating a new user account and enters a compromised password, the system will flag it and prevent the user from being created until the password is updated.
This does not mean that your Provet account has been breached. The password may have been exposed in another service’s data breach.
How to Create a Secure Password
To ensure your new password is secure:
Use a password that you have not used anywhere else.
Include uppercase and lowercase letters, numbers, and special characters.
Do not use identifiable information, such as the clinic name, your name, or email address. Even if the password has not been leaked, this type of information can make your account easier to target.
Consider using a password manager to create and store strong passwords.
Security and Privacy Commitment
Provet does not send your actual password to Have I Been Pwned. The integration only uses a partial hash to check against compromised passwords, which ensures your data remains private and secure.
Need Help?
If you cannot access your account or need help resetting your password, please contact Provet support.
