When an employee leaves, whether on good terms or not, their access to your systems should end promptly. Yet in many organizations accounts linger for weeks or months after the last day. Old logins are tempting for misuse, easy for attackers to take over and difficult to explain to a regulator. The HIPAA Security Rule includes a workforce security standard with termination procedures, which means you are expected to remove access when employment ends.
The key to doing this reliably is a shared process rather than a heroic effort by IT. Here is how to build one.
HR finishes paperwork but IT is never told
A manager tells IT at the end of the month rather than on the day
Staff members work at multiple facilities and one location misses the notification
Agency or contract staff are not in the HR system at all
Shared accounts mean nobody is sure which logins belong to whom
Cloud applications are managed by different department heads, outside IT's view
Designate one form or ticket type that starts the process, and make HR or the supervisor responsible for submitting it. Include:
Employee name, role and location
Last day and last hour of access
Whether the departure is voluntary or involuntary
Equipment to collect, such as laptops, phones, badges, keys and tablets
Special handling needs, such as forwarding email or transferring files
For involuntary terminations, coordinate timing so access ends at the moment the conversation takes place, not hours later.
Disable the main directory or single-sign-on account, which cuts off most connected applications at once
Revoke active sessions and tokens, since a disabled password does not always end an open session
Remove multi-factor authentication methods or registered devices
Disable remote access, VPN and virtual desktop accounts
Disable the EMR account, and any separate logins for clinical applications, pharmacy portals and billing systems
Wipe or remove work data from personal devices if mobile management is in use
Collect and log hardware, badges and keys
Reset any shared passwords the person knew, such as for a vendor portal or a shared mailbox
Forward email or grant a manager access to the mailbox for a limited period, according to policy
Transfer ownership of files, shared drives and calendar items
Update distribution lists and phone directories
Review the person's access logs for unusual activity near the departure date
Remove access to physical systems, such as door badges and camera software
Convert the mailbox to a shared mailbox or archive it, then delete it according to retention policy
Remove licenses to stop paying for unused subscriptions
Close out the device inventory entry
Contract and agency staff: Create accounts with automatic expiration dates matching the contract end, so access ends even if nobody remembers.
Physicians and consultants: Review access annually and remove those who no longer work with your organization.
Transfers: Moving to a different department also requires changing access. Removing the old permissions is as important as adding new ones.
Medical directors and vendors: Include them in access reviews, as they often retain accounts long after engagements end.
Once a quarter, compare your list of active accounts with your current HR roster.
Which accounts belong to nobody on the roster?
Which have not signed in for ninety days?
Which service accounts have no owner?
Which cloud applications are not connected to single sign-on?
This simple reconciliation catches many orphaned accounts. Document the review and keep the results for your compliance file.
Single sign-on dramatically simplifies offboarding, since disabling one identity closes access to many applications. Automated provisioning tools can synchronize account status from your HR system. Even without automation, a good checklist and a clear owner go a long way.
Treat departing employees with respect. Collect equipment and remind them of continuing confidentiality obligations regarding resident information. Where appropriate, an exit conversation can reveal gaps in processes or training.
Track how long accounts remain active after the last day. The goal is zero, with a same-day target. Share the metric with leadership, and investigate any exceptions.
UnityCare IT can help build offboarding procedures, audit lingering accounts and set up single sign-on to make access removal faster and more reliable. If you are not sure how many former staff still have active logins, we can find out with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172