When an employee leaves, the exit interview, final paycheck and returned badge are usually handled. Less reliable is the removal of their digital access. Accounts linger for months, former staff still receive email, and shared passwords they once knew stay unchanged. Each of these is an opening, whether for a disgruntled former employee or for an attacker who finds a forgotten account.
The HIPAA Security Rule requires procedures to terminate access to ePHI when employment ends or when access is no longer appropriate. A consistent offboarding process makes that requirement routine.
Former employees may still be able to reach resident records through email, remote access or cloud systems.
Dormant accounts are attractive to attackers because no one notices unusual activity.
Shared logins, wireless passwords and door codes that the person knew may remain valid.
Auditors and insurers often ask about timely deprovisioning.
Offboarding fails most often because IT does not hear about the departure. Create a simple link between HR and IT:
HR or the manager submits an offboarding request as soon as a resignation is received or a termination is decided.
The request includes the last working day and time, and whether the departure is friendly or sensitive.
IT confirms completion back to HR in writing.
For involuntary terminations, access should be disabled at the moment the meeting begins or just before it, coordinated between HR and IT.
Disable the user's main directory account and sign-in.
Revoke active sessions and tokens on cloud applications, and reset multi-factor authentication methods.
Remove access to the EMR and other clinical applications.
Disable VPN and remote access.
Remove the person from email groups, shared mailboxes and calendar delegations.
Remove access to shared folders and third-party portals such as pharmacy, therapy and supply ordering.
Remove them from the password manager and shared vaults.
Decide how email will be handled. Options include forwarding to a supervisor for a limited period, an automatic reply and later archiving.
Preserve files the organization needs, then archive or delete according to your retention policy.
Avoid deleting accounts immediately if there is a chance records are needed for an investigation or legal hold.
Collect laptops, tablets, phones, tokens and badges.
For personal devices with work access, remove work email and apps, or use remote wipe of the work container.
Wipe returned equipment securely before reassigning.
Update the asset inventory.
Change shared passwords the person knew, such as for social media accounts, vendor portals or shared workstation logins.
Consider changing door codes and wireless keys if they were shared with the person.
Review whether the employee had administrator rights anywhere and rotate those secrets.
Collect keys and badges and disable door access.
Update the roster of authorized contacts for vendors who take instructions from that person.
People accumulate access over time. Check for:
Accounts with vendors who knew the employee as a contact.
Mobile phone plans or text messaging apps.
Software licenses assigned to the person.
Scheduled reports or automations created under their account.
Service accounts or integrations running under their credentials.
Once a quarter, compare the list of active accounts to your current HR roster. Investigate and disable any account that does not match. Review contractor and agency accounts too, which often outlive their assignments.
Keep a record of what was removed and when, who approved it and who completed it. Documentation shows auditors and insurers that the process is real.
If someone leaves on bad terms, consider increased monitoring of their account activity during the final days, and review logs afterward for unusual downloads or forwarding rules. Coordinate with counsel and HR.
UnityCare IT helps healthcare and senior living organizations design offboarding workflows and audit for lingering accounts. If you are unsure how many former employees still have access, we can run an account review.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172