When an employee leaves, HR collects the badge and the keys. But what about the email account, the EHR login, the VPN, the cloud storage folder, the shared password list and the work data on a personal phone? In many organizations, those stay active for weeks or months, creating a quiet risk: a former employee, or anyone who has their credentials, can still get in.
The HIPAA Security Rule includes termination procedures for ending access when employment ends or when access is no longer appropriate. Here is a practical checklist to make that real.
Departing employees, especially those who leave on bad terms, may take or misuse data
Old accounts are attractive to attackers, because nobody is watching them
Unused accounts continue to cost money in licenses
Lingering access complicates audits and breach investigations
Resident information can remain on devices no longer under your control
HR knows about departures before IT does. The simplest fix is a shared process in which HR notifies IT as soon as a termination or resignation is decided, with the effective date and time. For involuntary terminations, access should often end at the moment of notification. For resignations, plan the last day and consider whether access should be limited during the notice period.
Disable the main user account in your directory or identity system, rather than deleting it right away, so data is preserved
Disable EHR access and remove roles, including any physician or contractor portals
Revoke VPN and remote access
Remove access to email, cloud storage and file shares
Terminate sessions on all devices, and reset the password
Remove from distribution lists, messaging platforms and shared mailboxes
Remove the person from MFA and password manager enrollment
Disable access to third-party portals the individual used, such as pharmacy, lab, payer or vendor sites
Change passwords for any shared accounts the person knew
Rotate wireless or door access codes if shared
Update vendor contacts and notification routing
Collect laptops, tablets, phones, tokens and security keys, and log their return
Remote wipe or remove the work profile from personal devices enrolled for work
Check for removable media and printed resident information
Securely wipe and reissue returned equipment, or record its disposal
Set up forwarding or an auto-reply as appropriate, and assign a manager to review the mailbox for needed items
Preserve data needed for legal, compliance or clinical reasons, according to retention policy
Transfer ownership of files and shared documents to a supervisor
Collect badges and keys, and deactivate access cards
Change alarm or lockbox codes if known
Remove from visitor and parking systems
Record the date and time each step was completed
Keep the record with HR files and in the IT ticket
Obtain a reminder acknowledgment of ongoing confidentiality obligations
When someone transfers departments, remove access they no longer need. "Permission creep" occurs when people accumulate access over the years, and it violates the minimum necessary principle.
Use accounts with automatic expiration dates tied to contract end dates, so access ends even if no one remembers to remove it.
When a contractor's engagement ends, disable their credentials and remote tools the same day. Ask vendors to notify you when their technicians leave their company.
Have a quick procedure that lets a supervisor or HR contact IT at any hour to cut access immediately.
Once a quarter, compare the list of active accounts with the current employee roster. Look for accounts with no recent activity, accounts belonging to people who have left and generic accounts without an owner. Fix what you find, and track how long it took to close access in each case.
No communication between HR and IT
Deleting an account immediately and losing important data or audit trails
Forgetting third-party systems that are managed outside IT
Leaving shared passwords unchanged
Not recovering devices or wiping them
We help organizations connect their HR processes to account management, so access ends reliably and is documented. If you suspect you have old accounts still active, we can run a review against your employee list and clean them up.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172