and if your host doesn't make mod_auth_mysql available for you for gods sake get the .htpasswd file out of the web accessible directory and into a secured area and at a minimum rename it.
There are a lot of precautions you can take so that your are more secure and most of them are easy to implement.
Most people use
http://mygreatpaysite.com/members/.htpasswd to store their password then wonder why they were hacked so easily.