When an employee leaves a care facility, the paperwork usually gets done: final paycheck, uniform return, exit interview. Access to computer systems is where things slip. Accounts stay active for weeks, shared passwords never change, and a former nurse still has an email account and EMR login long after her last shift.
This matters for security and for compliance. Dormant accounts are attractive to attackers because nobody notices when they are used. A disgruntled former employee with working credentials can cause real harm. HIPAA's Security Rule expects procedures for terminating access to electronic protected health information when employment ends, and a documented offboarding process is the simplest way to meet it.
Resignations, retirements and contract ends give you time to prepare. HR should notify IT as soon as a last day is confirmed.
Terminations require access to be removed at the moment of, or just before, the conversation. Coordinate in advance between HR, the supervisor and IT, so accounts are disabled while the employee is meeting with management.
An aide who becomes a unit clerk needs different access. Treat internal moves as partial offboarding, removing old access rather than piling on new.
Disable the main network, email and single sign-on account
Disable or reset EMR/EHR access, and any other clinical or billing system accounts
Remove access to VPN, remote desktop and cloud services
Revoke MFA registrations and remove registered phones or tokens
Disable badge and door access
Remove access to shared mailboxes, shared drives and group distribution lists
Check third-party systems with separate logins: pharmacy portals, state reporting systems, payroll, supply ordering, social media and the website
Change passwords on any shared accounts the person knew
Update vendor portal logins and wireless keys that they could access
Rotate administrator or service account passwords if the person had IT-level access
This is a strong argument for avoiding shared logins in the first place, since each one creates an offboarding task.
Collect laptops, tablets, phones, badges, keys and tokens
Wipe or reset returned devices before reassignment
Remove company data and email from personal phones, using device management where it is installed
Forward email and transfer files according to policy, usually to the supervisor, rather than leaving the mailbox accessible to the former employee
Preserve data when needed for legal or record retention purposes before deleting anything
Remind the employee of their continuing confidentiality obligations
Ask for any resident information held on personal devices or paper to be returned or deleted
Document the exit and the completion of each step
| Role | Responsibility | |---|---| | HR | Starts the process, notifies IT and the supervisor, handles timing for sensitive cases | | Supervisor | Identifies what the person had access to, collects equipment, redirects work | | IT | Disables accounts, handles devices and data, confirms completion | | Compliance or administrator | Reviews the log and handles any concerns about misuse |
A simple shared checklist or ticket template, completed each time, makes this routine.
Even good processes miss things. Every quarter:
Compare the list of active employees from HR with active accounts in your main systems
Look for accounts with no recent logins
Review agency, contractor and student accounts for expiration dates
Check vendor and consultant access lists
Accounts that cannot be tied to a current person should be disabled and investigated.
Agency and temporary staff should have accounts with automatic end dates.
Physicians and consultants who have access but are not employees still need regular access reviews.
Employees with extensive access, such as IT staff or administrators, need extra care, including credential rotation and review of recent activity.
Keep records of what was disabled, when and by whom. That documentation supports HIPAA compliance and helps answer questions if a former employee is later suspected of misusing information.
UnityCare IT can help you design an offboarding checklist, connect it to your HR process and run periodic access reviews to catch the accounts that slipped through. If you are unsure how many former employees still have active logins, we can find out.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172