Staffing agencies, therapy contractors, consultants, students and temporary workers are a regular presence in many care facilities. They are often vital to covering shifts. They also arrive with little notice, work for a short time, and may never go through the same onboarding as employees. From a security perspective, they can fall through the cracks, with shared logins, lingering accounts and unknown training status. A light but consistent process closes those gaps without making it hard to staff the building.
Fast starts. Shifts need to be filled quickly, so access is often granted informally.
Short tenure. Accounts created for one-week assignments can live on for years.
Mixed employers. The person is not your employee, so your normal HR checks and training may not apply.
Shared devices. Agency staff typically use facility computers, carts and tablets.
Unclear accountability. If something goes wrong, who is responsible, you or the agency?
Under HIPAA, workforce members include employees, volunteers, trainees and others whose conduct is under the direct control of the covered entity, whether or not they are paid by it. That means you generally need to train them and manage their access the same way. Agencies themselves may be business associates in some arrangements, depending on the services provided and whether they handle PHI, so check your contracts with legal counsel.
Before the first placement, make sure your contract with each agency or contractor addresses:
Confidentiality and HIPAA compliance obligations, and whether a business associate agreement is needed.
Training: what the agency provides, and what you will provide on site.
Background checks and credential verification, to the extent permitted and required.
Notification of incidents, including lost badges, suspected misuse or misdirected information.
Return of equipment and removal of access at the end of assignments.
Prohibitions on bringing personal storage devices, photographing residents or copying records.
Build a short process that can be completed before or at the start of the first shift.
The agency or scheduler sends the person's name, role, dates and shift details through an agreed channel.
IT or the designated administrator creates a named, role-based account that expires on the last scheduled day, with an easy way to extend it.
Access is limited to what the role needs, usually the EMR role matching the position and nothing else. Avoid email or file share access unless needed.
Verify identity and credentials, and issue a temporary badge.
Complete a short orientation of about fifteen minutes that covers privacy basics, safe handling of PHI, no sharing of logins, how to log in, how to lock the screen, how to report problems and who to call for help.
Have the person sign a confidentiality statement and acknowledgment.
Enroll multi-factor authentication if applicable, or use a method suited to shared devices, such as badge login.
Use unique accounts so audit logs show who did what.
Review access logs periodically for unusual activity.
Give them a point of contact on the unit for questions.
Accounts expire automatically on the end date.
Badges and keys are returned, and sign-in records closed.
Review the list of active contractor accounts weekly and remove anything stale.
For agency staff who return often, keep a roster of approved individuals with records of training and signed acknowledgments. This can allow faster access on subsequent shifts while keeping accounts disabled between assignments rather than deleted, if your policy permits. Refresh training at least annually.
Provide lockers for personal belongings and phones away from resident care areas, if your policy limits phones.
Do not permit USB drives or personal laptops on the facility network.
Place a printed one-page reminder at nurse stations.
Contractors who document in their own systems, such as outside therapy companies or pharmacies, may have their own electronic records and connections. Treat them as vendors, with a business associate agreement, vendor risk review and controlled network access.
Maintain a log of contractors with training dates, acknowledgments and account dates. Auditors, surveyors and insurers may ask for evidence of how non-employees are handled.
UnityCare IT can help you design a fast contractor onboarding process, set up auto-expiring accounts and run periodic reviews of non-employee access. If your current process is a shared login on a sticky note, we can help you replace it without slowing down staffing.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172