What Happens When an Employee Leaves? A HIPAA Checklist for Offboarding Staff
By Nicole Statley at Healthcare Compliance Pros
Every practice has an
onboarding checklist. Far fewer have a real offboarding one, and that gap is a
HIPAA problem, not just an HR oversight. When a workforce member with access to
protected health information (PHI) leaves, the HIPAA Security Rule requires
your practice to have a documented process for cutting off that access. Skip
it, delay it, or fail to document it, and you have a compliance finding waiting
to happen.
Here's what the rule
actually requires, why timing matters, and a full checklist you can use for
every departure, voluntary or not.
Why Offboarding Is a HIPAA Requirement
The HIPAA Security Rule's
Workforce Security standard requires covered entities and business associates
to implement termination procedures. Specifically, this means "procedures
for terminating access to electronic protected health information when the
employment of, or other arrangement with, a workforce member ends" (45 CFR
§ 164.308(a)(3)(ii)(C)).
This is listed as an
"addressable" implementation specification. That doesn't mean
optional. It means your practice must either implement it as written or
document an equivalent alternative measure and explain why that alternative is
reasonable and appropriate for your organization. In practice, nearly every
healthcare organization implements it directly, since there's rarely a good
reason not to revoke a departed employee's access to PHI.
This requirement applies no
matter how big or small your practice is. A two-provider office with no formal
HR department is just as bound by 45 CFR § 164.308(a)(3)(ii)(C) as a large
hospital system. If your staff can log into an EHR, billing system, or patient
portal, you have a termination-procedures obligation the moment that person's
role ends.
Timing: Immediate vs. Delayed Revocation
The current Security Rule
doesn't specify an exact number of hours or minutes for revoking access. It
requires that procedures exist and get followed consistently. That said, the
accepted compliance standard, reflected across OCR guidance and audit
expectations, is straightforward:
- Involuntary separation: Revoke access before or at the moment the employee is notified of termination. If the person can still log in after learning they've been let go, you've created a window for retaliatory data access or deletion.
- Voluntary separation (resignation, retirement): Revoke access no later than the end of the employee's final scheduled shift. There's no grace period. Access shouldn't carry into the next business day.
Delayed revocation is one of
the most common findings in HIPAA offboarding failures. It's usually not
malicious. It's a ticket that sits in an IT queue, a manager who assumes
someone else handled it, or a system that got missed because it wasn't the "main"
login. The fix isn't a faster IT team. It's a checklist that doesn't rely on
memory.
One clarification worth
making here: HHS issued a Notice of Proposed Rulemaking (NPRM) in December 2024
that would, if finalized, require notifying certain regulated entities within
24 hours when a workforce member's ePHI access is changed or terminated. That
proposal is not part of the current binding Security Rule yet. Practices should
aim for "immediate" revocation as best practice today, but shouldn't
treat a proposed rule as already in effect.
The Full Offboarding Checklist
A real offboarding process
covers more ground than most practices assume. Break it into four categories
and assign an owner to each.
Systems access
- EHR and practice management system logins
- Email accounts (disable, don't just forward)
- VPN and remote desktop access
- Shared drives and cloud storage (Google Drive, OneDrive, Dropbox)
- Single sign-on (SSO) and any connected third-party apps
Physical access
- Building keys and key cards
- ID badges (deactivate in the access control system, not just collect the card)
- Door codes, especially shared codes multiple staff use, which need to be changed rather than revoked for one person only
Devices
- Collect all company-owned laptops, tablets, phones, and USB drives
- For BYOD (bring-your-own-device) arrangements, verify and document that organizational PHI has been removed or wiped from the personal device. Don't just take the employee's word for it.
Credentials
- Deactivate unique logins (disable, don't delete, so audit trails stay intact)
- Rotate every shared password the employee had access to: admin accounts, Wi-Fi, alarm codes, shared platform logins
Special Risk Windows
Departing employees
represent a heightened risk period. Industry research on insider data theft
consistently points to the weeks before a resignation as the highest-risk
window, with some studies estimating that a large share of intellectual
property or data theft by departing employees happens in the final 90 days of
employment, often before the resignation is even announced.
For practices with the
technical capability to do so, this means paying closer attention during notice
periods to:
- Unusual USB transfer activity
- Spikes in print jobs involving patient records
- Email attachments containing PHI sent to personal accounts
Not every practice has the
IT infrastructure for real-time monitoring, and that's okay. The point isn't to
install surveillance tools overnight. It's to recognize that the notice period
itself is a risk window, so access review shouldn't wait until the literal last
day.
Documentation: What Auditors Want to See
A termination procedure that
isn't documented is, from an audit standpoint, indistinguishable from no
procedure at all. If OCR investigates a breach or conducts a compliance review,
they'll ask for evidence, not just a policy statement claiming you revoke
access when employees leave.
That evidence should
include:
- An offboarding ticket or checklist for each departure, listing every system and physical access point, with an assigned owner and a completion date and time for each step
- Confirmation that no logins occurred after the termination date, which typically means a documented audit log review
- Chain-of-custody records for returned devices: what was returned, when, and confirmation of data wipe status for personal devices
- Retention of all of the above for six years from the date the record was created or last in effect, per the HIPAA documentation retention requirement at 45 CFR § 164.316(b)(2)(i)
If your current process is a
verbal handoff between the departing employee's manager and IT, you have a
policy gap and a documentation gap at the same time.
Common Mistakes Small Practices Make
Three patterns show up again
and again in smaller healthcare organizations.
Shared logins never get
changed. A generic front-desk login or shared scheduling account gets used by
multiple staff over the years, and no one owns updating the password when
someone leaves. Lesser-used systems get forgotten. The EHR and email get handled,
but the patient portal admin console, the e-fax service, or the secure texting
platform get overlooked because they're not top-of-mind. And there's no single
point of ownership. When offboarding responsibility is split across a manager,
IT, and HR with no one accountable for the full checklist, steps fall through
the cracks, and no one notices until an audit or a breach investigation asks
for records that don't exist.
Building a Repeatable Process
The fix for all three
mistakes above is structural, not about trying harder:
- Assign one owner, typically the compliance officer or a designated office manager, responsible for the entire offboarding checklist regardless of who else is involved in individual steps.
- Use the same standardized checklist every time, whether the departure is a retirement, a resignation, or a termination for cause. Consistency is what makes the process defensible in an audit.
- Reinforce confidentiality obligations at exit. A brief exit conversation reminding the departing employee that HIPAA confidentiality duties don't end with employment is a low-effort step that reinforces how seriously the practice takes the requirement.
Conclusion and Next Steps
Offboarding is one of the
most predictable events in any practice's operations, which makes it one of the
easiest compliance gaps to close. The checklist above covers systems, physical
access, devices, and credentials, but the piece that actually protects your
practice in an audit is the documentation trail showing who did what, and when.
If your practice doesn't
currently have a written termination procedure that maps to 45 CFR §
164.308(a)(3)(ii)(C), that's the first gap to close. Healthcare Compliance Pros
can help you build or audit your offboarding policy, checklist, and
documentation practices as part of a broader HIPAA compliance program review.
Ready to close the gap?
Schedule a HIPAA policy review with our team to assess your current offboarding
process against Security Rule requirements.
FAQ
Is HIPAA termination procedure a required or addressable
specification?
It's listed as "addressable" under 45 CFR § 164.308(a)(3)(ii)(C),
meaning your organization must implement it or document a reasonable equivalent
alternative. In practice, nearly all healthcare organizations implement it
directly.
How fast does access have to be revoked under current HIPAA rules?
The current Security Rule doesn't specify an exact time limit. It requires a
documented, consistently applied procedure. The accepted standard is to revoke
access before or at the moment of notification for involuntary terminations,
and by the end of the final shift for voluntary departures.
Does the proposed 24-hour or one-hour HIPAA rule already apply?
No. That timeline comes from a December 2024 Notice of Proposed Rulemaking that
hasn't been finalized. The current binding rule remains in effect until any
final rule is published.
How long do we need to keep offboarding documentation?
At least six years from the date the record was created or last in effect,
under the HIPAA documentation retention requirement at 45 CFR §
164.316(b)(2)(i).
Do small practices without an HR department still need a formal
offboarding process?
Yes. The Security Rule's termination procedure requirement applies to any
covered entity or business associate with workforce members who access ePHI,
regardless of practice size or whether a dedicated HR function exists.
What's the single most common offboarding failure?
Shared credentials, meaning logins or passcodes used by multiple staff, that
never get changed after one of those staff members leaves.