Quarterly PointClickCare Access Reviews: A Practical Routine

Every long-term care facility accumulates user accounts. A new nurse is hired, an agency aide covers a few weeks, a manager changes departments, a contractor finishes a project. Accounts get created quickly because people need to work. They are removed slowly, if at all. Over a year, the result is a list of users, some of whom no longer work for you, and some of whom hold far more access than their current job requires.

A quarterly access review is the cure. It does not require special tools, only a calendar reminder, a few hours and a clear owner. This post describes a routine that works for most facilities and companies using PointClickCare or a similar electronic health record.

Why this matters

Resident records are among the most sensitive information you hold. HIPAA's Security Rule expects covered entities to limit access to the minimum necessary and to review information system activity and access. Beyond compliance, stale accounts are a practical risk. A former employee's login that still works is an open door. An account with broad rights, but a user who only needs to view charts, magnifies the damage if that password is ever stolen.

Before you start

Decide on three things.

Who owns the review. One named person, often the administrator or compliance lead, with a backup. IT can pull the list, but the business decides who should have access.

Who attests. Department heads, such as the DON, business office manager and social services director, confirm whether each person in their area still needs access and at what level.

Where results are recorded. A simple spreadsheet or signed checklist, saved by date, shows an auditor that the review happened.

Step 1: Export the current user list

Have an administrator export or print the list of active users with their assigned roles or permission groups. Include the last login date if your system provides it. If you cannot get all of this from one screen, gather what you can and note the gaps. The point is a snapshot you can compare against reality.

Step 2: Compare against HR

Give the list to HR or payroll and ask them to mark anyone who has left, transferred or gone on extended leave. Do the same for agency staff and contractors, where records are often scattered. Anyone not on your current roster is a candidate for immediate removal. Disable first, then delete only according to your records policy, so that audit trails remain.

Step 3: Check roles against jobs

For each department, ask the supervisor to review their staff and answer one question: does this person's access match what they do today? Look especially for:

Staff who changed jobs but kept old permissions.

Users with administrator-level rights who are not administrators.

Shared logins, which should be replaced with individual accounts.

Generic or test accounts that were never removed.

Vendor or consultant accounts that are no longer needed.

A hypothetical example

Imagine a 120-bed skilled nursing facility where a nurse moves into a unit manager role. Her new job needs additional reporting access, but nobody removes her old medication-entry rights from a previous float assignment. Meanwhile, a business office employee who left six months ago still has an active account. Neither shows up until someone looks at the full list.

Step 4: Look at dormant accounts

Accounts that have not logged in for 60 to 90 days deserve a question. Some are legitimate, such as seasonal or PRN staff. Others are forgotten. Set a rule, for example, that dormant accounts are disabled after a defined period and reactivated on request.

Step 5: Make the changes and document them

Submit change requests, apply them, and record what was removed or modified, by whom and when. Keep the signed attestations from department heads. Review administrators separately and more carefully, since their accounts carry the most risk.

Making it stick

Put the review on the calendar for the same week each quarter.

Connect it to onboarding and offboarding, so most changes happen in real time and the quarterly review catches only exceptions.

Require multi-factor authentication wherever it is offered.

Track how many exceptions you find each quarter. A falling number means your day-to-day process is improving.

If you would like help building the checklist, pulling user lists or tying account removal to your HR process, UnityCare IT works with long-term care operators across Oklahoma, Texas and Arkansas on exactly this kind of routine.

Related service

Keeping PointClickCare and other EHR systems fast, connected and available.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172