HIPAA offboarding checklist with laptop, security icons, ID badge, keys, and clipboard on office desk.

What Happens When an Employee Leaves? A HIPAA Checklist for Offboarding Staff

What Happens When an Employee Leaves? A HIPAA Checklist for Offboarding Staff

By Nicole Statley at Healthcare Compliance Pros

Every practice has an onboarding checklist. Far fewer have a real offboarding one, and that gap is a HIPAA problem, not just an HR oversight. When a workforce member with access to protected health information (PHI) leaves, the HIPAA Security Rule requires your practice to have a documented process for cutting off that access. Skip it, delay it, or fail to document it, and you have a compliance finding waiting to happen.

Here's what the rule actually requires, why timing matters, and a full checklist you can use for every departure, voluntary or not.

Why Offboarding Is a HIPAA Requirement

The HIPAA Security Rule's Workforce Security standard requires covered entities and business associates to implement termination procedures. Specifically, this means "procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends" (45 CFR § 164.308(a)(3)(ii)(C)).

This is listed as an "addressable" implementation specification. That doesn't mean optional. It means your practice must either implement it as written or document an equivalent alternative measure and explain why that alternative is reasonable and appropriate for your organization. In practice, nearly every healthcare organization implements it directly, since there's rarely a good reason not to revoke a departed employee's access to PHI.

This requirement applies no matter how big or small your practice is. A two-provider office with no formal HR department is just as bound by 45 CFR § 164.308(a)(3)(ii)(C) as a large hospital system. If your staff can log into an EHR, billing system, or patient portal, you have a termination-procedures obligation the moment that person's role ends.

Timing: Immediate vs. Delayed Revocation

The current Security Rule doesn't specify an exact number of hours or minutes for revoking access. It requires that procedures exist and get followed consistently. That said, the accepted compliance standard, reflected across OCR guidance and audit expectations, is straightforward:

  • Involuntary separation: Revoke access before or at the moment the employee is notified of termination. If the person can still log in after learning they've been let go, you've created a window for retaliatory data access or deletion.
  • Voluntary separation (resignation, retirement): Revoke access no later than the end of the employee's final scheduled shift. There's no grace period. Access shouldn't carry into the next business day.

Delayed revocation is one of the most common findings in HIPAA offboarding failures. It's usually not malicious. It's a ticket that sits in an IT queue, a manager who assumes someone else handled it, or a system that got missed because it wasn't the "main" login. The fix isn't a faster IT team. It's a checklist that doesn't rely on memory.

One clarification worth making here: HHS issued a Notice of Proposed Rulemaking (NPRM) in December 2024 that would, if finalized, require notifying certain regulated entities within 24 hours when a workforce member's ePHI access is changed or terminated. That proposal is not part of the current binding Security Rule yet. Practices should aim for "immediate" revocation as best practice today, but shouldn't treat a proposed rule as already in effect.

The Full Offboarding Checklist

A real offboarding process covers more ground than most practices assume. Break it into four categories and assign an owner to each.

Systems access

  • EHR and practice management system logins
  • Email accounts (disable, don't just forward)
  • VPN and remote desktop access
  • Shared drives and cloud storage (Google Drive, OneDrive, Dropbox)
  • Single sign-on (SSO) and any connected third-party apps

Physical access

  • Building keys and key cards
  • ID badges (deactivate in the access control system, not just collect the card)
  • Door codes, especially shared codes multiple staff use, which need to be changed rather than revoked for one person only

Devices

  • Collect all company-owned laptops, tablets, phones, and USB drives
  • For BYOD (bring-your-own-device) arrangements, verify and document that organizational PHI has been removed or wiped from the personal device. Don't just take the employee's word for it.

Credentials

  • Deactivate unique logins (disable, don't delete, so audit trails stay intact)
  • Rotate every shared password the employee had access to: admin accounts, Wi-Fi, alarm codes, shared platform logins

Special Risk Windows

Departing employees represent a heightened risk period. Industry research on insider data theft consistently points to the weeks before a resignation as the highest-risk window, with some studies estimating that a large share of intellectual property or data theft by departing employees happens in the final 90 days of employment, often before the resignation is even announced.

For practices with the technical capability to do so, this means paying closer attention during notice periods to:

  • Unusual USB transfer activity
  • Spikes in print jobs involving patient records
  • Email attachments containing PHI sent to personal accounts

Not every practice has the IT infrastructure for real-time monitoring, and that's okay. The point isn't to install surveillance tools overnight. It's to recognize that the notice period itself is a risk window, so access review shouldn't wait until the literal last day.

Documentation: What Auditors Want to See

A termination procedure that isn't documented is, from an audit standpoint, indistinguishable from no procedure at all. If OCR investigates a breach or conducts a compliance review, they'll ask for evidence, not just a policy statement claiming you revoke access when employees leave.

That evidence should include:

  • An offboarding ticket or checklist for each departure, listing every system and physical access point, with an assigned owner and a completion date and time for each step
  • Confirmation that no logins occurred after the termination date, which typically means a documented audit log review
  • Chain-of-custody records for returned devices: what was returned, when, and confirmation of data wipe status for personal devices
  • Retention of all of the above for six years from the date the record was created or last in effect, per the HIPAA documentation retention requirement at 45 CFR § 164.316(b)(2)(i)

If your current process is a verbal handoff between the departing employee's manager and IT, you have a policy gap and a documentation gap at the same time.

Common Mistakes Small Practices Make

Three patterns show up again and again in smaller healthcare organizations.

Shared logins never get changed. A generic front-desk login or shared scheduling account gets used by multiple staff over the years, and no one owns updating the password when someone leaves. Lesser-used systems get forgotten. The EHR and email get handled, but the patient portal admin console, the e-fax service, or the secure texting platform get overlooked because they're not top-of-mind. And there's no single point of ownership. When offboarding responsibility is split across a manager, IT, and HR with no one accountable for the full checklist, steps fall through the cracks, and no one notices until an audit or a breach investigation asks for records that don't exist.

Building a Repeatable Process

The fix for all three mistakes above is structural, not about trying harder:

  • Assign one owner, typically the compliance officer or a designated office manager, responsible for the entire offboarding checklist regardless of who else is involved in individual steps.
  • Use the same standardized checklist every time, whether the departure is a retirement, a resignation, or a termination for cause. Consistency is what makes the process defensible in an audit.
  • Reinforce confidentiality obligations at exit. A brief exit conversation reminding the departing employee that HIPAA confidentiality duties don't end with employment is a low-effort step that reinforces how seriously the practice takes the requirement.

Conclusion and Next Steps

Offboarding is one of the most predictable events in any practice's operations, which makes it one of the easiest compliance gaps to close. The checklist above covers systems, physical access, devices, and credentials, but the piece that actually protects your practice in an audit is the documentation trail showing who did what, and when.

If your practice doesn't currently have a written termination procedure that maps to 45 CFR § 164.308(a)(3)(ii)(C), that's the first gap to close. Healthcare Compliance Pros can help you build or audit your offboarding policy, checklist, and documentation practices as part of a broader HIPAA compliance program review.

Ready to close the gap? Schedule a HIPAA policy review with our team to assess your current offboarding process against Security Rule requirements.

FAQ

Is HIPAA termination procedure a required or addressable specification?
It's listed as "addressable" under 45 CFR § 164.308(a)(3)(ii)(C), meaning your organization must implement it or document a reasonable equivalent alternative. In practice, nearly all healthcare organizations implement it directly.

How fast does access have to be revoked under current HIPAA rules?
The current Security Rule doesn't specify an exact time limit. It requires a documented, consistently applied procedure. The accepted standard is to revoke access before or at the moment of notification for involuntary terminations, and by the end of the final shift for voluntary departures.

Does the proposed 24-hour or one-hour HIPAA rule already apply?
No. That timeline comes from a December 2024 Notice of Proposed Rulemaking that hasn't been finalized. The current binding rule remains in effect until any final rule is published.

How long do we need to keep offboarding documentation?
At least six years from the date the record was created or last in effect, under the HIPAA documentation retention requirement at 45 CFR § 164.316(b)(2)(i).

Do small practices without an HR department still need a formal offboarding process?
Yes. The Security Rule's termination procedure requirement applies to any covered entity or business associate with workforce members who access ePHI, regardless of practice size or whether a dedicated HR function exists.

What's the single most common offboarding failure?
Shared credentials, meaning logins or passcodes used by multiple staff, that never get changed after one of those staff members leaves.