Offboarding Done Right: Closing Access the Day Someone Leaves

When an employee leaves a care facility, the paperwork usually gets done: final paycheck, uniform return, exit interview. Access to computer systems is where things slip. Accounts stay active for weeks, shared passwords never change, and a former nurse still has an email account and EMR login long after her last shift.

This matters for security and for compliance. Dormant accounts are attractive to attackers because nobody notices when they are used. A disgruntled former employee with working credentials can cause real harm. HIPAA's Security Rule expects procedures for terminating access to electronic protected health information when employment ends, and a documented offboarding process is the simplest way to meet it.

Build the Process Around Three Triggers

1. Planned departures

Resignations, retirements and contract ends give you time to prepare. HR should notify IT as soon as a last day is confirmed.

2. Sudden or involuntary departures

Terminations require access to be removed at the moment of, or just before, the conversation. Coordinate in advance between HR, the supervisor and IT, so accounts are disabled while the employee is meeting with management.

3. Role changes and transfers

An aide who becomes a unit clerk needs different access. Treat internal moves as partial offboarding, removing old access rather than piling on new.

The Offboarding Checklist

Accounts and access

Disable the main network, email and single sign-on account

Disable or reset EMR/EHR access, and any other clinical or billing system accounts

Remove access to VPN, remote desktop and cloud services

Revoke MFA registrations and remove registered phones or tokens

Disable badge and door access

Remove access to shared mailboxes, shared drives and group distribution lists

Check third-party systems with separate logins: pharmacy portals, state reporting systems, payroll, supply ordering, social media and the website

Shared credentials

Change passwords on any shared accounts the person knew

Update vendor portal logins and wireless keys that they could access

Rotate administrator or service account passwords if the person had IT-level access

This is a strong argument for avoiding shared logins in the first place, since each one creates an offboarding task.

Devices and data

Collect laptops, tablets, phones, badges, keys and tokens

Wipe or reset returned devices before reassignment

Remove company data and email from personal phones, using device management where it is installed

Forward email and transfer files according to policy, usually to the supervisor, rather than leaving the mailbox accessible to the former employee

Preserve data when needed for legal or record retention purposes before deleting anything

Reminders and acknowledgments

Remind the employee of their continuing confidentiality obligations

Ask for any resident information held on personal devices or paper to be returned or deleted

Document the exit and the completion of each step

Who Does What

| Role | Responsibility | |---|---| | HR | Starts the process, notifies IT and the supervisor, handles timing for sensitive cases | | Supervisor | Identifies what the person had access to, collects equipment, redirects work | | IT | Disables accounts, handles devices and data, confirms completion | | Compliance or administrator | Reviews the log and handles any concerns about misuse |

A simple shared checklist or ticket template, completed each time, makes this routine.

Check for Orphans Regularly

Even good processes miss things. Every quarter:

Compare the list of active employees from HR with active accounts in your main systems

Look for accounts with no recent logins

Review agency, contractor and student accounts for expiration dates

Check vendor and consultant access lists

Accounts that cannot be tied to a current person should be disabled and investigated.

Special Cases

Agency and temporary staff should have accounts with automatic end dates.

Physicians and consultants who have access but are not employees still need regular access reviews.

Employees with extensive access, such as IT staff or administrators, need extra care, including credential rotation and review of recent activity.

Document It

Keep records of what was disabled, when and by whom. That documentation supports HIPAA compliance and helps answer questions if a former employee is later suspected of misusing information.

How UnityCare IT Helps

UnityCare IT can help you design an offboarding checklist, connect it to your HR process and run periodic access reviews to catch the accounts that slipped through. If you are unsure how many former employees still have active logins, we can find out.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172