Password changes are captured in the security audit journal. It might be a good idea to track this activity for sensitive user profiles.
More information about running audit journal reports
When a user profile is changed in any way, a CP record is generated to the system security journal. If the change includes a password change, the new password is not shown but an indicator is set in the journal record that confirms that a password was changed. If other changes are made to the profile, the specific new values changed to are reported.
Our iEventMonitor product can be configured to watch for password (and other user profile) changes.