Who Has the Password?
Passwords are quietly becoming an estate planning issue. Why password management matters more as scams targeting older adults grow, and practical, low-drama ways to get ahead of it together.
Digital asset management is one of the newer corners of the legal system, and it’s catching up to real life more slowly than most of us would like. Being named a digital power of attorney, someone legally authorized to manage a person’s online accounts, is becoming more common in updated estate documents, but plenty of existing wills and powers of attorney were written before anyone thought to mention email, online banking logins, or cloud storage at all.
Most states have adopted some version of a law called RUFADAA, the Revised Uniform Fiduciary Access to Digital Assets Act, which is meant to give a named agent or executor a legal path to a person’s digital accounts. In practice, it’s a narrower path than it sounds. Companies can still refuse a request they consider burdensome, can require a court order, and in many cases won’t hand over the contents of private communications like email or messages unless the account holder explicitly consented in advance. The law helps. It doesn’t replace the far simpler thing: someone actually knowing the passwords, or having a legitimate way to get them, before they’re needed.
Why This Matters More Now
Older adults and people managing new health conditions are being targeted for fraud at a scale worth taking seriously. FBI data for 2025 put reported losses from Americans 60 and older at more than $7.7 billion, across over 200,000 complaints, a 59% increase from the year before. The FTC has separately noted that the median reported loss for people 60 and up was the highest of any age group. Compromised accounts, a reused password, an old email address nobody checks anymore, a login shared carelessly, are often part of how these losses start. Getting passwords organized isn’t paranoia. It’s one of the more concrete things a family can do to close an actual door.
Making It Easier, Not Heavier
None of this needs to turn into a project that feels like a burden on top of everything else. A few approaches that tend to make it manageable:
- Use a shared vault instead of a single point of failure. A shared vault is really just a locked digital box that two or more people can open, so access doesn’t live on one phone or in one person’s memory. Family or couple plans on tools like 1Password or Bitwarden let you set this up. LastPass offers something similar, though it’s worth comparing current pricing and security track records before choosing.
- Google Password Manager is a reasonable starting point. If your care recipient already uses Chrome or an Android phone, it’s already there, free, and requires no new app or account. It’s a lower bar to clear than a dedicated password manager, which matters if the goal is simply getting started.
- Ask to be added rather than asking for a takeover. For banking, utilities, and other financial accounts, becoming an authorized user or joint account holder is often both easier logistically and more in line with what the institution actually requires, compared to just obtaining someone else’s password.
- Treat it as a shared afternoon, not a private task. Sitting down together to go through accounts, one at a time, gives you a natural opening to talk about why this matters, protecting against fraud, making sure nothing gets locked out later, without it feeling like you’re taking something away. It can help your care recipient feel like a participant in the plan instead of its subject.
- Name it explicitly in your legal documents. If your power of attorney or will predates this conversation, it may not mention digital assets at all. An elder law attorney can help update it so a designated person has a clearer legal basis to act, rather than relying on RUFADAA’s narrower default protections alone.
The Security Question Trick
One tip from the group worth passing along: some caregivers find it helpful to agree, in advance, on a shared answer to the security question on accounts you both may need to access. Banks and other sites often ask things like “what was your first pet’s name” or “what street did you grow up on,” and if your care recipient’s real answer is something only they’d know or remember, that question can become its own locked door later, sometimes at the worst possible moment. Settling on one answer together now, and writing it down in the same place as the passwords, means a security question is less likely to be the thing standing between you and an account you’re otherwise entitled to access.
It’s worth knowing the tradeoff. Security questions are already a weaker layer of protection than a password, precisely because answers like a childhood street or a pet’s name can sometimes be guessed or found by someone else. Making the answer identical across accounts means that if it’s ever guessed, it opens more than one door at once. For most families this trade, a bit less theoretical security in exchange for not being locked out during a medical emergency, feels worth it. It’s just worth making that choice knowingly rather than by accident.
Making Sense of Two-Factor Authentication
Many accounts now ask for something beyond a password before letting you in, usually a code sent by text, a code from an app, or a prompt on a phone. This is called two-factor authentication, or 2FA, and it exists to make an account harder to break into. It also has a real, practical downside for caregivers: if the code goes only to your care recipient’s phone, and their phone is lost, off, or hard for them to use, you can end up locked out of an account you legitimately need.
A few ways to make this less of a trap:
- Ask if a phone call or a second phone number can be added. Many services let you register more than one number or a backup method for receiving that code. Adding your own number, alongside theirs, means a code isn’t stranded on a single device.
- Print and store backup codes when the option is offered. Most services that use 2FA generate a set of one-time backup codes when it’s first turned on, meant for exactly this situation, a lost or unavailable device. These are easy to overlook in the setup process, but worth asking for and keeping with the passwords, on paper, somewhere secure.
- Set it up together, once, rather than solving it in a panic later. Turning on 2FA and finding these backup options takes a few minutes with both of you at the computer. Finding them out for the first time while locked out of an account is a much worse afternoon.
- It’s fine to ask a bank or provider’s support line for help. Most institutions have staff used to walking people through exactly this. Asking isn’t a sign you’ve done something wrong. It’s the fastest way through.
None of this has to happen all at once. Even one afternoon spent organizing the handful of accounts that matter most, banking, health portals, email, can close most of the gap, and it’s a rare task that protects both your peace of mind and theirs at the same time.
Resources
Carefull: Financial safety and fraud protection built specifically for older adults, already in the OU2 resource library under Tools & Apps.
Don’t Forget Your Digital POA: A plain-language look at how new state laws are handling digital power of attorney.