|

The Last-Day Access Checklist for Small Healthcare Practices

The Last-Day Access Checklist for Small Healthcare Practices

A departing employee can disappear from the schedule at 5 p.m. and still remain active in half a dozen systems the next morning.

That is easy to miss in a small medical or dental practice. The office manager may handle payroll, the electronic health record vendor may control user accounts, and a billing company may manage a separate portal. Add email, cloud storage, e-prescribing, remote access, alarm codes, shared tablets, and vendor logins, and “turn off the account” stops being one task.

For practices covered by HIPAA, the Security Rule calls for procedures to terminate access to electronic protected health information when a workforce member’s employment or other arrangement ends.[4] The rule covers more than employees. HHS’s audit protocol defines workforce members to include on-site contractors, students, and volunteers, and its termination review looks for deactivated system access, recovered access devices, time frames, and documentation that access ended promptly.[1]

This article is practical guidance, not a legal opinion or a HIPAA compliance determination. The checklist gives a small practice a workable starting point. Your systems, contracts, and risk analysis may require more.

Start before the person’s last hour

Offboarding works better when one person owns the checklist and the practice agrees on timing before the departure becomes public.

For a routine departure, the practice manager, privacy or security lead, and IT provider should confirm the person’s final working time and list the systems they use. For an involuntary or higher-risk departure, coordinate the timing with employment counsel and disable access when the organization decides it should end. Do not improvise the sequence in front of the departing worker.

Name one coordinator. That person does not need to perform every technical step, but they should know who is responsible for each one and collect proof when it is complete.

Build the access list from the work, not from memory

Start with the person’s job. A front-desk employee, hygienist, biller, and outside IT technician will not have the same access.

Check these areas:

  • electronic health record and practice-management systems;
  • email, calendars, shared drives, chat, and cloud storage;
  • billing, claims, payment, payroll, and banking portals;
  • e-prescribing, lab, imaging, referral, and patient communication services;
  • remote desktop, virtual private network, Wi-Fi, password manager, and multifactor authentication;
  • laptops, phones, tablets, keys, badges, door codes, alarm codes, and hardware tokens;
  • vendor support portals, website accounts, social media, and any application approved outside the normal IT process.

Ask the person’s manager and IT provider to review the list separately. One may remember a clinical system while the other finds a local account, shared mailbox, or remote-access tool.

HHS lists prompt credential revocation for departing employees, contractors, affiliates, and volunteers among its essential healthcare cybersecurity goals.[2] NIST’s Cybersecurity Framework also calls for access permissions and authorizations to be defined in policy, managed, enforced, reviewed, and limited by least privilege.[3] A reusable system list turns those broad outcomes into something a small practice can carry out.

Disable access without destroying the record

Disabling an account is usually safer than deleting it immediately. Deletion can remove mail, files, ownership information, or audit history that the practice still needs. The exact method depends on the product, so ask the system owner or vendor how to preserve business records while blocking sign-in.

At the agreed time:

  1. Block the user’s sign-in and terminate active sessions.
  2. Remove remote access, application tokens, and registered authentication methods.
  3. Revoke physical access, including keys, badges, door codes, and alarm codes.
  4. Recover practice-owned devices and check that they are accounted for before reuse.
  5. Transfer ownership of shared files, calendars, mailboxes, scheduled tasks, and business contacts.
  6. Remove the person from groups, mailing lists, shared credentials, and vendor-authorized contact lists.
  7. Rotate any password, code, or recovery method the person knew and that cannot be tied to an individual account.

Do not sign in as the former worker to keep a process running. Assign a new owner through the application’s administrative tools. If a device cannot be recovered, document that fact and follow the practice’s incident and device-management procedures rather than marking the task complete.

Look for the account behind the account

The visible login is not always the only path back in.

A former employee may still have an authenticated phone, a browser session, an application password, an email forwarding rule, a shared mailbox, or a personal address set as an account-recovery method. They may also own an automation that sends appointment reminders or moves files between systems.

Check active sessions and registered devices where the product provides that view. Review forwarding and delegation on business email. Confirm that recovery email addresses and phone numbers belong to the practice. Reassign integrations and scheduled jobs to a managed business identity.

This is also the right time to ask whether the person ever used a shared account. Shared access makes individual offboarding harder because the practice cannot revoke one person’s use without changing the credential for everyone. Record each shared account you find, rotate it now, and plan to replace it with named accounts where the system allows.

Keep a short offboarding record

A checked box is useful only if it says what was checked.

For each departure, retain a record with:

  • the person’s name, role, and workforce relationship;
  • the approved date and time for access to end;
  • the systems, devices, and physical-access items reviewed;
  • the action taken for each item, who performed it, and when;
  • exceptions, missing devices, failed steps, and the person assigned to follow up;
  • a final verification by someone other than the person who performed the shutdown, when practical.

HHS’s audit protocol says reviewers may request documentation showing that workforce access to ePHI was terminated and assess whether the timing matched the entity’s policies and procedures.[1] Keep evidence that is proportionate and readable: an exported account-status report, service ticket number, administrator confirmation, or signed checklist may be enough to show what happened. Avoid collecting passwords or unnecessary patient information in the offboarding file.

Store the completed record with restricted administrative or compliance files, not in a public team folder. Set retention according to the practice’s legal, contractual, and records-management requirements.

Verify again after the departure

The coordinator should run a second check after the shutdown. Confirm that sign-in is blocked, remote sessions are closed, devices are accounted for, and open exceptions have owners and due dates.

Then review recent access logs for the affected systems if those logs are available. The point is not to accuse the former worker. It is to catch an account that remained active, an unexpected session, or a process that broke when access changed.

HHS’s audit protocol treats job changes as an access issue too, not only departures. It asks whether privileges were adjusted when a job description changed and whether the change was documented.[1] Use the same checklist, with a narrower scope, for transfers, promotions, extended leave, and contractor changes.

Test the checklist with one recent departure

Pick someone who left in the past few months and reconstruct the process without changing any records. Can you identify every account they had? Can you show when access ended? Did anyone confirm the shutdown? Are shared passwords or vendor portals still unresolved?

The gaps you find become the next version of the checklist. Add missing systems, assign owners, and decide what evidence the practice will keep. A one-page procedure that people follow is more useful than a long policy nobody opens.

For practical guidance on cybersecurity and safer AI use, subscribe to Cyber & AI Insights.

If your practice needs employee cybersecurity training and documentation support, schedule a conversation with Your Data Guardian.

Sources

  1. HHS HIPAA Audit Protocol
  2. HHS Healthcare and Public Health Cybersecurity Performance Goals
  3. NIST Cybersecurity Framework 2.0
  4. 45 CFR 164.308 — Administrative safeguards

Similar Posts