@rmd1023 Periodic password changes are bad, but there are other requirements in NIST 800-63B that must be in place before eliminating password changes.
For example: password filtering (to prevent the creation/continued use of weak/compromised passwords) and password storage requirements are an integral part of 800-63B.
if MyChart is unwilling or incapable of providing the additional protections required, periodic password changes are the superior choice.
Ultimately, the best solution is for MyChart to take the steps required to eliminate password changes, but there’s so much for to 800-63B than “if you like your password, you can now keep it as long as you like!”