New employees form a lasting impression in their first hours. A new nurse who spends the morning waiting for a login, or a business office hire who cannot print, starts out frustrated. Meanwhile, a former employee whose account is still active months after leaving is a security problem waiting to happen.
A simple, shared checklist between human resources, department managers and IT prevents both. Here is a template you can adapt.
IT should receive the new hire's name, role, department, start date, manager and work location at least a week before arrival. For agency or contract staff, include the end date.
Create standard access profiles. A nurse needs the EHR, a time clock and email, perhaps, while a business office employee needs billing software and shared drives. Role-based templates reduce mistakes and prevent people from collecting unnecessary access over the years. This supports the HIPAA minimum necessary principle.
Create a unique username and email account
Assign appropriate security groups and application access
Enroll the person in multifactor authentication on day one
Prepare EHR access following your vendor's process, which may require manager approval
Assign and configure a workstation, laptop or tablet, if needed
Confirm updates, encryption and endpoint protection are installed
Set up phone extension, badge or access card, and printer access
Record the asset in your inventory
Ten to fifteen minutes covers the essentials:
How to log in, set a passphrase and enroll in MFA
How to reach the helpdesk, including after hours
Acceptable use expectations, including personal devices and social media
How to recognize and report phishing
Where resident information may and may not be stored or sent
HIPAA requires training for workforce members as appropriate to their roles. Complete and document initial training, and have the person sign acknowledgments for relevant policies.
Sit with the new hire while they sign in to each system. Check printing, phone, email and any shared drives. It is much easier to fix problems then than later.
Ask the manager whether anything is missing
Check that the person has used MFA successfully
Review any access requests that arose
Offboarding deserves equal attention.
HR notifies IT as soon as separation is known, ideally before the last day for planned departures
Disable accounts at the time of departure, or immediately for involuntary terminations
Reset passwords, remove MFA devices and revoke active sessions
Remove access to the EHR, email, remote access and cloud applications
Recover laptops, phones, badges and keys, and wipe devices according to policy
Forward email or give the manager access for a limited, documented period
Update shared passwords the person knew, and better yet, eliminate shared passwords
Remove the person from distribution lists and vendor portals
Use time-limited accounts that expire automatically. Provide the minimum access needed.
When a person changes roles, remove access they no longer need rather than layering new access on old.
Ship equipment ahead, with instructions, and schedule a video call for first login.
Track how long it takes to provision a new hire and how long it takes to disable access after separation. Quarterly, compare the HR roster with active accounts. Any account without a matching person needs an explanation.
A checklist only works if it is used. Make it part of HR's standard process, with a ticket created automatically for each hire and departure.
UnityCare IT supports onboarding and offboarding for healthcare organizations, from account creation to equipment setup. If your new hires are waiting on logins or you are unsure which former employees still have access, we can help sort it out.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172