Every long-term care facility accumulates user accounts. A new nurse is hired, an agency aide covers a few weeks, a manager changes departments, a contractor finishes a project. Accounts get created quickly because people need to work. They are removed slowly, if at all. Over a year, the result is a list of users, some of whom no longer work for you, and some of whom hold far more access than their current job requires.
A quarterly access review is the cure. It does not require special tools, only a calendar reminder, a few hours and a clear owner. This post describes a routine that works for most facilities and companies using PointClickCare or a similar electronic health record.
Resident records are among the most sensitive information you hold. HIPAA's Security Rule expects covered entities to limit access to the minimum necessary and to review information system activity and access. Beyond compliance, stale accounts are a practical risk. A former employee's login that still works is an open door. An account with broad rights, but a user who only needs to view charts, magnifies the damage if that password is ever stolen.
Decide on three things.
Who owns the review. One named person, often the administrator or compliance lead, with a backup. IT can pull the list, but the business decides who should have access.
Who attests. Department heads, such as the DON, business office manager and social services director, confirm whether each person in their area still needs access and at what level.
Where results are recorded. A simple spreadsheet or signed checklist, saved by date, shows an auditor that the review happened.
Have an administrator export or print the list of active users with their assigned roles or permission groups. Include the last login date if your system provides it. If you cannot get all of this from one screen, gather what you can and note the gaps. The point is a snapshot you can compare against reality.
Give the list to HR or payroll and ask them to mark anyone who has left, transferred or gone on extended leave. Do the same for agency staff and contractors, where records are often scattered. Anyone not on your current roster is a candidate for immediate removal. Disable first, then delete only according to your records policy, so that audit trails remain.
For each department, ask the supervisor to review their staff and answer one question: does this person's access match what they do today? Look especially for:
Staff who changed jobs but kept old permissions.
Users with administrator-level rights who are not administrators.
Shared logins, which should be replaced with individual accounts.
Generic or test accounts that were never removed.
Vendor or consultant accounts that are no longer needed.
Imagine a 120-bed skilled nursing facility where a nurse moves into a unit manager role. Her new job needs additional reporting access, but nobody removes her old medication-entry rights from a previous float assignment. Meanwhile, a business office employee who left six months ago still has an active account. Neither shows up until someone looks at the full list.
Accounts that have not logged in for 60 to 90 days deserve a question. Some are legitimate, such as seasonal or PRN staff. Others are forgotten. Set a rule, for example, that dormant accounts are disabled after a defined period and reactivated on request.
Submit change requests, apply them, and record what was removed or modified, by whom and when. Keep the signed attestations from department heads. Review administrators separately and more carefully, since their accounts carry the most risk.
Put the review on the calendar for the same week each quarter.
Connect it to onboarding and offboarding, so most changes happen in real time and the quarterly review catches only exceptions.
Require multi-factor authentication wherever it is offered.
Track how many exceptions you find each quarter. A falling number means your day-to-day process is improving.
If you would like help building the checklist, pulling user lists or tying account removal to your HR process, UnityCare IT works with long-term care operators across Oklahoma, Texas and Arkansas on exactly this kind of routine.
Keeping PointClickCare and other EHR systems fast, connected and available.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172