Offboarding Staff: Closing Access Gaps the Day They Leave

When an employee leaves, the exit interview, final paycheck and returned badge are usually handled. Less reliable is the removal of their digital access. Accounts linger for months, former staff still receive email, and shared passwords they once knew stay unchanged. Each of these is an opening, whether for a disgruntled former employee or for an attacker who finds a forgotten account.

The HIPAA Security Rule requires procedures to terminate access to ePHI when employment ends or when access is no longer appropriate. A consistent offboarding process makes that requirement routine.

Why it matters

Former employees may still be able to reach resident records through email, remote access or cloud systems.

Dormant accounts are attractive to attackers because no one notices unusual activity.

Shared logins, wireless passwords and door codes that the person knew may remain valid.

Auditors and insurers often ask about timely deprovisioning.

Build the trigger

Offboarding fails most often because IT does not hear about the departure. Create a simple link between HR and IT:

HR or the manager submits an offboarding request as soon as a resignation is received or a termination is decided.

The request includes the last working day and time, and whether the departure is friendly or sensitive.

IT confirms completion back to HR in writing.

For involuntary terminations, access should be disabled at the moment the meeting begins or just before it, coordinated between HR and IT.

The offboarding checklist

Accounts and access

Disable the user's main directory account and sign-in.

Revoke active sessions and tokens on cloud applications, and reset multi-factor authentication methods.

Remove access to the EMR and other clinical applications.

Disable VPN and remote access.

Remove the person from email groups, shared mailboxes and calendar delegations.

Remove access to shared folders and third-party portals such as pharmacy, therapy and supply ordering.

Remove them from the password manager and shared vaults.

Data and mail

Decide how email will be handled. Options include forwarding to a supervisor for a limited period, an automatic reply and later archiving.

Preserve files the organization needs, then archive or delete according to your retention policy.

Avoid deleting accounts immediately if there is a chance records are needed for an investigation or legal hold.

Devices

Collect laptops, tablets, phones, tokens and badges.

For personal devices with work access, remove work email and apps, or use remote wipe of the work container.

Wipe returned equipment securely before reassigning.

Update the asset inventory.

Shared credentials

Change shared passwords the person knew, such as for social media accounts, vendor portals or shared workstation logins.

Consider changing door codes and wireless keys if they were shared with the person.

Review whether the employee had administrator rights anywhere and rotate those secrets.

Physical

Collect keys and badges and disable door access.

Update the roster of authorized contacts for vendors who take instructions from that person.

Do not forget the less obvious accounts

People accumulate access over time. Check for:

Accounts with vendors who knew the employee as a contact.

Mobile phone plans or text messaging apps.

Software licenses assigned to the person.

Scheduled reports or automations created under their account.

Service accounts or integrations running under their credentials.

Review regularly

Once a quarter, compare the list of active accounts to your current HR roster. Investigate and disable any account that does not match. Review contractor and agency accounts too, which often outlive their assignments.

Document it

Keep a record of what was removed and when, who approved it and who completed it. Documentation shows auditors and insurers that the process is real.

A note on sensitive departures

If someone leaves on bad terms, consider increased monitoring of their account activity during the final days, and review logs afterward for unusual downloads or forwarding rules. Coordinate with counsel and HR.

How UnityCare IT can help

UnityCare IT helps healthcare and senior living organizations design offboarding workflows and audit for lingering accounts. If you are unsure how many former employees still have access, we can run an account review.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172