now would be a good time to turn on 2 factor authentication if you aren't using it already
Good advice regardless of this heartbleed mess. Turn it on anywhere you can. Places I have 2 factor authentication enabled:
outlook.com
gmail/google apps
Amazon AWS
godaddy
Even turn it on for your gaming accounts, even if you don't care about them. Every account hacked gives away some personal information that can be used to try to get into other accounts you own...
And never use the same password for more than 1 account! Use a password safe. For the accounts that you have to have passwords that you can remember, see this classic XKCD:
http://xkcd.com/936/If you don't need to know the password by heart, use a very long random string and keep it in a password safe. You're also protected against keyloggers this way since you are never actually typing the password - how could you, it's impossible for any sane person to know
