The steps to take to address this issue will depend on the e-mail provider and e-mail application used.
Google "not receiving incoming mail after password change" plus your e-mail account provider's and application's names for specific information.
Personally, if I found that someone was using my e-mail account, I'd delete (or have my ISP delete it they issued it) and then make a new one. I wouldn't rely on a password change.
After that is done, make sure that your sister knows not to give out her password to anyone, be it friend, family member, or "significant other." Also, don't write it down and keep it where prying eyes can find it. Make your passwords secure but also easy to remember. For instance, "My stupid 12 CATs!"