Offboarding Employees: Ending System Access on the Last Day

When an employee leaves, whether on good terms or not, their access to your systems should end promptly. Yet in many organizations accounts linger for weeks or months after the last day. Old logins are tempting for misuse, easy for attackers to take over and difficult to explain to a regulator. The HIPAA Security Rule includes a workforce security standard with termination procedures, which means you are expected to remove access when employment ends.

The key to doing this reliably is a shared process rather than a heroic effort by IT. Here is how to build one.

Why delays happen

HR finishes paperwork but IT is never told

A manager tells IT at the end of the month rather than on the day

Staff members work at multiple facilities and one location misses the notification

Agency or contract staff are not in the HR system at all

Shared accounts mean nobody is sure which logins belong to whom

Cloud applications are managed by different department heads, outside IT's view

Build a simple offboarding trigger

Designate one form or ticket type that starts the process, and make HR or the supervisor responsible for submitting it. Include:

Employee name, role and location

Last day and last hour of access

Whether the departure is voluntary or involuntary

Equipment to collect, such as laptops, phones, badges, keys and tablets

Special handling needs, such as forwarding email or transferring files

For involuntary terminations, coordinate timing so access ends at the moment the conversation takes place, not hours later.

Checklist for IT

Same day

Disable the main directory or single-sign-on account, which cuts off most connected applications at once

Revoke active sessions and tokens, since a disabled password does not always end an open session

Remove multi-factor authentication methods or registered devices

Disable remote access, VPN and virtual desktop accounts

Disable the EMR account, and any separate logins for clinical applications, pharmacy portals and billing systems

Wipe or remove work data from personal devices if mobile management is in use

Collect and log hardware, badges and keys

Reset any shared passwords the person knew, such as for a vendor portal or a shared mailbox

Within a few days

Forward email or grant a manager access to the mailbox for a limited period, according to policy

Transfer ownership of files, shared drives and calendar items

Update distribution lists and phone directories

Review the person's access logs for unusual activity near the departure date

Remove access to physical systems, such as door badges and camera software

Within a few weeks

Convert the mailbox to a shared mailbox or archive it, then delete it according to retention policy

Remove licenses to stop paying for unused subscriptions

Close out the device inventory entry

Special situations

Contract and agency staff: Create accounts with automatic expiration dates matching the contract end, so access ends even if nobody remembers.

Physicians and consultants: Review access annually and remove those who no longer work with your organization.

Transfers: Moving to a different department also requires changing access. Removing the old permissions is as important as adding new ones.

Medical directors and vendors: Include them in access reviews, as they often retain accounts long after engagements end.

Audit regularly

Once a quarter, compare your list of active accounts with your current HR roster.

Which accounts belong to nobody on the roster?

Which have not signed in for ninety days?

Which service accounts have no owner?

Which cloud applications are not connected to single sign-on?

This simple reconciliation catches many orphaned accounts. Document the review and keep the results for your compliance file.

Reduce reliance on manual steps

Single sign-on dramatically simplifies offboarding, since disabling one identity closes access to many applications. Automated provisioning tools can synchronize account status from your HR system. Even without automation, a good checklist and a clear owner go a long way.

Do not forget the human side

Treat departing employees with respect. Collect equipment and remind them of continuing confidentiality obligations regarding resident information. Where appropriate, an exit conversation can reveal gaps in processes or training.

Document and measure

Track how long accounts remain active after the last day. The goal is zero, with a same-day target. Share the metric with leadership, and investigate any exceptions.

UnityCare IT can help build offboarding procedures, audit lingering accounts and set up single sign-on to make access removal faster and more reliable. If you are not sure how many former staff still have active logins, we can find out with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172