Few IT tasks cause more daily friction in a care facility than account setup. A new nurse arrives for orientation and cannot sign in. A departing employee still has access to the EHR weeks later. Both are process problems rather than technology problems, and both are fixable with a checklist and clear ownership.
Here is a practical approach for onboarding and offboarding in long-term care, senior living and clinic settings.
The HIPAA Security Rule requires procedures for authorizing access to electronic protected health information, and for terminating access when employment ends. Auditors and insurers often ask how quickly former employees lose access. A documented, repeatable process is your best answer.
The biggest cause of delay is late notice. Human resources should send IT a standard request as soon as an offer is accepted, not on the morning of orientation.
Full name, job title, department and supervisor
Start date and shift or location
The role, which defines what access they need
Whether they need a phone extension, a badge or a medication cart login
Whether they will use a facility device or a personal one
Create standard access profiles such as RN, CNA, medication aide, activities, dietary, business office and administrator. Each profile lists the systems and permissions that role requires. This avoids the common habit of copying another employee's access, which tends to accumulate extra permissions over time.
Verify the employee's identity before handing over credentials
Have them set a password themselves and enroll in multi-factor authentication
Provide a one-page quick guide for common tasks and the helpdesk number
Have the employee sign the acceptable use and confidentiality policies
Complete HIPAA and security awareness training before granting access to resident records, where practical
Test every system in front of them so surprises appear during orientation
People move between roles, such as an aide who becomes a med tech or a nurse who becomes a unit manager. Each change should trigger a review. Add the access required for the new role and remove what is no longer needed. Access creep is common and rarely noticed until an audit.
Access should end at the moment of departure, or earlier for involuntary terminations. Coordinate with human resources so IT is told in advance when a termination is planned.
Disable the network and email accounts
Disable access to the EHR and any other clinical or billing applications
Remove access to remote tools, VPN and mobile device management
Collect laptops, tablets, phones, badges and keys
Change shared passwords the person knew, such as shared logins for equipment
Forward or delegate email and files to the supervisor, then archive as policy requires
Remove the person from distribution lists, group chats and vendor portals
Record the date and time each step was completed
Staff often have logins to pharmacy portals, supplier websites, state reporting systems and social media. Keep a list of which roles use which outside accounts so they can be closed or transferred.
Every quarter, compare the list of active accounts against the current employee roster. Look for accounts that belong to people no longer employed, unused accounts and generic logins. This single review catches most of the problems that slip through.
The process only works if someone owns it. Typically human resources triggers the request, IT performs the work and a manager verifies completion. Document the steps, and track turnaround times so you can see whether new hires are waiting.
UnityCare IT can provide a ready-to-use onboarding and offboarding workflow for your facility, and our helpdesk can handle account changes quickly so new staff are productive from their first shift.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172