Back to Blog
August 24, 2026 5 min read

An Employee Just Left Your Practice. Is Your Patient Data Still Secure?

Offboarding is a compliance event, not just an HR one

When a staff member leaves, most practices handle the obvious steps — final paycheck, returning a key, an exit conversation. What frequently gets skipped is the security side: that employee likely still has an active login to the practice management system, a mobile app connected to patient scheduling, maybe VPN or remote-desktop access set up months ago for a snow day that never came. None of that disappears on its own the moment someone walks out.

HIPAA treats this as an access control failure, not an HR oversight. A former employee who can still log in — whether they ever intend to or not — means the practice no longer controls who can see protected health information, and "we forgot" is not a defense OCR accepts.

What has to be revoked, and how fast

The standard is immediate revocation, ideally effective the same day employment ends — not "sometime this week" once the front desk gets around to it. That means disabling the practice management system login, removing the employee from any patient portal or texting platform, pulling building and alarm codes, collecting or remotely wiping any practice-owned device, and removing them from shared email or cloud storage accounts.

For a termination where the employee may be upset, this needs to happen before or during the exit conversation, not after — a delay of even a few hours has been the difference between a clean offboarding and an actual incident in cases HHS has investigated.

The access practices forget to close

The obvious systems get remembered. What gets missed are the secondary ones: a shared password to a scheduling app that never got reset because it's used by three other people too, a personal phone with the practice email account still logged in from working remotely once, access to a billing portal that was set up by a vendor and never routed through the practice's own user list, or a former office manager who still has admin rights on the website or Google Business profile.

Any login that was ever shared instead of assigned individually is a login that's nearly impossible to fully close off after someone leaves — which is itself one of the more common findings when a compliance audit reviews access control.

How to make this a checklist instead of a scramble

The fix is a written offboarding procedure that exists before you need it: a list of every system, app, and physical access point tied to a role, so that when someone leaves, closing access is a matter of working down a list rather than trying to remember everything from memory in the moment. Individual logins for every employee — no shared passwords — make that list actually enforceable.

Building that access inventory and offboarding checklist is part of what we set up in a compliance audit and keep current through Managed Compliance, so practices in Nashville, Hendersonville, Gallatin, Lebanon, and Mount Juliet have a same-day answer ready the next time someone hands in their badge.

Not sure where your practice stands?

Get a free 30-minute readiness check — no pressure, just clarity on what you need.

Get My Free Readiness Check