Well it depends on how much you're concerned about extra security. If you have a Control/Admin Panel provided by your hosting company, you can change DB password in there and then in config.inc.php file.
You can also remove DB information from config.inc.php altogether and place it in separate file
<?php
$config['dbtype'] = "mysql";
$config['dbserver'] = "localhost";
$config['dbuser'] = "blah";
$config['dbpass'] = "blahblah";
$config['dbname'] = "blah";
?>
behind public html directory, you should have some sort of protected folder provided by your hosting company. Then you can include this separate file in the config.inc.php
include("/usr/home/blahblah/protected/separateconfig.php");
However, if you save threads configuration from the CP it will overwrite config.inc.php to its original condition, so you will have to modify CP as well (*sigh*)
I suppose if you're on Unix you can move config.inc.php into protected directory and tell your server to look for it there, via symlink or something.
I would personally just change the password, but then again I do not know your set up, so never mind.