Most security planning focuses on outside attackers, but some of the most damaging incidents begin with someone who used to work there. A terminated employee whose account still works, a contractor whose access was never removed, or a manager who quietly copied files before leaving: all of these are insider incidents, and they are often easier to prevent than a sophisticated attack.
Healthcare and senior-living organizations face particular risk. Turnover is high, staff move between facilities, and many people share systems that contain protected health information. This post covers how departing employees cause harm and which controls reduce the chance of it.
Not every case is malicious. Some are careless. But the patterns are consistent.
The most common pattern is simple: the person is gone, but their account is not. Email, records-system access, remote access, cloud applications and shared passwords may all remain active. Anyone with those credentials, including the former employee, can sign in.
Employees who know they are leaving sometimes copy files, resident lists, contact information or business documents to personal email, cloud storage or USB drives. Even when intent is to help in a future job, taking protected information may violate policy and HIPAA.
A disgruntled person with administrative access can delete files, change settings, lock others out or disable backups. This risk is highest for IT staff, managers with admin rights, and anyone who controls shared accounts.
Former or soon-departing staff may look up information on residents, coworkers or acquaintances. Snooping is a recognized privacy violation and a reportable concern.
Shared logins, such as a generic account for a unit workstation or a vendor portal, are a persistent problem. When someone leaves, the password they know does not change unless someone remembers to change it.
A written checklist, owned by HR and IT together, is the single most effective control. It should cover:
Notification to IT before or at the time of departure, not days later
Disabling the primary account at the agreed moment, which for involuntary terminations may be before the person is told
Revoking remote access, VPN, mobile email and application sign-ins
Collecting devices, badges, keys and tokens
Changing passwords for any shared accounts the person knew
Removing access to cloud applications, vendor portals and third-party systems
Redirecting or preserving the mailbox according to policy
Documenting that every step was completed
People should have only the access their job requires. That limits what a departing person could copy or damage and makes offboarding simpler. Review administrative privileges regularly and keep them to a small, named group.
Consider controls that reduce easy copying:
Restrict or log use of USB storage on workstations that handle sensitive data
Block or alert on forwarding to personal email addresses
Monitor large downloads or unusual file access, especially in the weeks before someone leaves
Use data loss prevention features in your email and file platform where available
Audit logs for email, file storage and the record system help you answer what a person accessed. Confirm that logs are on, retained for a reasonable period, and reviewed when something looks wrong.
Give each person a unique login so access can be removed without disrupting everyone else. Where sharing cannot be avoided, keep a list of who knows each credential and rotate it when anyone leaves.
Make sure that no single person can delete both production data and backups. Use separate credentials for backup systems and require multi-factor authentication for administrators.
Terminations carry emotional weight, and timing matters. Coordinate with HR so access is removed at the right moment. For high-risk situations, such as an IT administrator leaving on bad terms, plan changes ahead of time: rotate administrative passwords, review recent changes, and confirm who else can recover control of key systems.
Offboarding catches people who leave. Periodic access reviews catch the gaps. Every quarter, have managers confirm that everyone with access to key systems still works there and still needs that access.
Preserve evidence, including logs, and avoid altering affected systems unnecessarily.
Disable access immediately.
Involve HR and legal counsel before confronting the individual.
Assess whether protected health information was involved and whether notification under the HIPAA Breach Notification Rule is required.
Notify your cyber insurance carrier if applicable.
UnityCare IT helps healthcare organizations build offboarding checklists that connect HR and IT, review who has access to what, and turn on the logging that makes investigations possible. Our goal is to make sure departures are routine events instead of security incidents.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172