Offboarding Checklist: Closing Access When Staff Leave

When an employee leaves, HR collects the badge and the keys. But what about the email account, the EHR login, the VPN, the cloud storage folder, the shared password list and the work data on a personal phone? In many organizations, those stay active for weeks or months, creating a quiet risk: a former employee, or anyone who has their credentials, can still get in.

The HIPAA Security Rule includes termination procedures for ending access when employment ends or when access is no longer appropriate. Here is a practical checklist to make that real.

Why timely offboarding matters

Departing employees, especially those who leave on bad terms, may take or misuse data

Old accounts are attractive to attackers, because nobody is watching them

Unused accounts continue to cost money in licenses

Lingering access complicates audits and breach investigations

Resident information can remain on devices no longer under your control

Build the process around triggers

HR knows about departures before IT does. The simplest fix is a shared process in which HR notifies IT as soon as a termination or resignation is decided, with the effective date and time. For involuntary terminations, access should often end at the moment of notification. For resignations, plan the last day and consider whether access should be limited during the notice period.

The checklist

Accounts and access

Disable the main user account in your directory or identity system, rather than deleting it right away, so data is preserved

Disable EHR access and remove roles, including any physician or contractor portals

Revoke VPN and remote access

Remove access to email, cloud storage and file shares

Terminate sessions on all devices, and reset the password

Remove from distribution lists, messaging platforms and shared mailboxes

Remove the person from MFA and password manager enrollment

Disable access to third-party portals the individual used, such as pharmacy, lab, payer or vendor sites

Shared credentials

Change passwords for any shared accounts the person knew

Rotate wireless or door access codes if shared

Update vendor contacts and notification routing

Devices and media

Collect laptops, tablets, phones, tokens and security keys, and log their return

Remote wipe or remove the work profile from personal devices enrolled for work

Check for removable media and printed resident information

Securely wipe and reissue returned equipment, or record its disposal

Email and data

Set up forwarding or an auto-reply as appropriate, and assign a manager to review the mailbox for needed items

Preserve data needed for legal, compliance or clinical reasons, according to retention policy

Transfer ownership of files and shared documents to a supervisor

Physical access

Collect badges and keys, and deactivate access cards

Change alarm or lockbox codes if known

Remove from visitor and parking systems

Documentation

Record the date and time each step was completed

Keep the record with HR files and in the IT ticket

Obtain a reminder acknowledgment of ongoing confidentiality obligations

Special cases

Role changes

When someone transfers departments, remove access they no longer need. "Permission creep" occurs when people accumulate access over the years, and it violates the minimum necessary principle.

Temporary and agency staff

Use accounts with automatic expiration dates tied to contract end dates, so access ends even if no one remembers to remove it.

Vendors and contractors

When a contractor's engagement ends, disable their credentials and remote tools the same day. Ask vendors to notify you when their technicians leave their company.

Emergency terminations

Have a quick procedure that lets a supervisor or HR contact IT at any hour to cut access immediately.

Audit periodically

Once a quarter, compare the list of active accounts with the current employee roster. Look for accounts with no recent activity, accounts belonging to people who have left and generic accounts without an owner. Fix what you find, and track how long it took to close access in each case.

Common mistakes

No communication between HR and IT

Deleting an account immediately and losing important data or audit trails

Forgetting third-party systems that are managed outside IT

Leaving shared passwords unchanged

Not recovering devices or wiping them

Help from UnityCare IT

We help organizations connect their HR processes to account management, so access ends reliably and is documented. If you suspect you have old accounts still active, we can run a review against your employee list and clean them up.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172