In senior living and long-term care, staff turnover is a fact of life. People leave on good terms and bad, give notice or simply stop showing up, and move to a competitor down the road. Each departure creates a small IT task that is easy to forget: shutting off access. Left undone, it leaves behind active accounts that could be used by the former employee, or by an attacker who has found the credentials. Closing access promptly is one of the simplest and highest-value habits you can build.
The HIPAA Security Rule includes workforce security and access management requirements, including procedures for terminating access to ePHI when employment ends or when access is no longer appropriate. Beyond compliance, there are practical reasons:
A former employee with an active account could view resident records they no longer have any reason to see.
Dormant accounts are attractive to attackers because no one notices unusual activity.
Company-owned laptops, phones, badges and keys that are not returned are loose ends.
Auditors, surveyors and insurers may ask for proof that terminations are handled promptly.
The biggest challenge is not technical. It is communication. IT cannot disable what it does not know about. Make it a rule that HR or the supervisor notifies IT on the day a resignation or termination is decided, and sets the actual cutoff time. For involuntary terminations, coordinate so access is disabled at the moment the conversation ends, not a day later.
A simple form or ticket category called Employee Exit, with required fields for name, last day, cutoff time and supervisor, keeps this consistent. Weekly cross-checks of the payroll or HR termination list against active accounts catch anything missed.
Disable the user's main directory or domain account at the cutoff time. Disable rather than delete at first, so data and audit history are preserved.
Revoke EMR and other clinical application access, including any separate vendor portals.
Remove multi-factor authentication registrations and security tokens.
Disable VPN, remote access and cloud application accounts.
Change passwords on any shared credentials the person knew, such as vendor portals or shared mailboxes.
Remove the user from distribution lists, groups and shared drives.
Disable building access, door codes and alarm codes, and collect badges and keys.
Revoke access to the nurse call system, phone system and voicemail, and reassign the extension.
Convert the mailbox to a shared mailbox or set an auto-reply, and assign a supervisor to review messages for a defined period.
Preserve the mailbox and files according to your retention policy. Do not delete data that may be needed for legal or compliance reasons.
Transfer ownership of important documents to the supervisor.
Remove the person's email from mobile devices.
Collect laptops, tablets, phones, chargers, tokens and any other assets, and check them against your inventory.
For personal devices with work data, remove the managed work profile or app data remotely.
Wipe and reimage returned computers before reissue, and record the date.
If equipment is not returned, document efforts to recover it and consider whether remote wipe is appropriate.
Record the date and time each action was completed and who did it.
Ask the supervisor to confirm that access was removed and equipment returned.
Keep the checklist with HR records according to your retention policy. HIPAA documentation requirements call for retention for six years.
Agency and contract staff: Set an expiration date on accounts when they are created, then confirm with the agency at the end of the assignment.
Employees who transfer: A role change is also a reason to adjust access. Remove old permissions rather than layering new ones on top.
Sudden departures: Have a process that lets a supervisor or administrator request an urgent lockout by phone at any hour.
Administrators and IT staff: Their departure deserves extra care, since they may hold privileged credentials, backups and vendor accounts. Rotate administrator passwords and review remote management tools.
Even with a solid process, mistakes happen. Every quarter, have department heads review a list of everyone with access to their systems and confirm that each person should still have it. Look for accounts with no recent logins, which are good candidates for disabling.
A departure checklist takes minutes per employee and prevents a category of risk that otherwise accumulates silently. UnityCare IT builds onboarding and offboarding workflows with healthcare HR teams and can run an account cleanup to find stale access in your systems today.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172