Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Priority Intake
Cybersecurity

The Day Someone Leaves: A Medical Practice Offboarding Checklist

Aug 25, 2026·3 min read·By Ric Acevedo

Someone hands in their notice, or worse, does not. Within an hour their EHR login is disabled and everyone assumes it is handled. It usually is not, and the gap is rarely the EHR.

What access should a medical practice disable when an employee leaves?

Every system that can reach patient information, not just the EHR: email, the practice management system, billing and payer portals, online fax, telehealth, shared drives and cloud storage, the password manager, VPN or remote access, physical keys and alarm codes, and any shared login the person knew. The Security Rule expects a documented termination procedure, and the documentation is as much the requirement as the act.

The list, in the order that matters

Immediately — before the conversation ends, if it is involuntary

  1. Disable the account, do not delete it. Deleting destroys the audit trail and often the mailbox with it. Disable, then decide later.
  2. Revoke active sessions. Disabling an account does not always kick out a session already running on a phone. This is the step most people miss.
  3. Reset any shared password they knew. The front-desk login, the fax account, the alarm code. If a generic credential was in use, the named account being disabled changes nothing.
  4. Remove remote access. VPN, remote desktop, whatever the practice uses out of hours.

Same day

  1. Email. Convert to a shared mailbox or forward, rather than deleting. Referrals and results keep arriving for weeks.
  2. Every external portal. Payer portals, clearinghouse, labs, imaging, e-prescribing. These live outside your control and each needs contacting separately — this is the part that takes actual time.
  3. Mobile devices. If the practice email was on a personal phone, remove it. If you cannot, that tells you something about your mobile policy worth fixing.
  4. Physical. Keys, badges, alarm codes, the drawer in the back office.

Within the week

  1. Review what they had access to that nobody realised. Shared drives accumulate permissions nobody audits.
  2. Write it down. Who left, when, each item, who did it, and the date. Keep it six years like everything else.

The two failures we see most

The generic login. A shared front-desk account, a fax service everyone uses, a scanner with a saved password. Named accounts get disabled diligently; shared ones are invisible on the checklist because they belong to nobody. Access technically continues after separation.

The forgotten integration. Someone connected a scheduling tool, a transcription service or an AI note-taker to their work account months ago. Disabling the user does not always revoke the token that tool holds. We ran this check on our own company and found ChatGPT still holding read access to every file we owned — granted by one person, invisible, with no expiry. A departing employee’s connected apps deserve the same look.

What to do before you need it

The practices that handle this well are not the ones with better software. They have a one-page list, a named person who owns it, and a copy of the list that does not live in that person’s head. Write it on a calm Tuesday, because the day you need it will not be one.

If you would like a second opinion on what your practice would actually miss, we are glad to walk through it — and if the answer is that you have it covered, we will say so. Related reading: what to do in the first hour when a device goes missing.

General information about a regulation, not legal advice.

Recent Articles

Cybersecurity
What a Lakeland Medical Practice Should Expect From IT Support
Aug 25, 2026
Cybersecurity
Why Warehouse Wi-Fi Fails in Polk County Distribution Buildings
Aug 25, 2026
Cybersecurity
RingCentral vs 8x8 vs Nextiva: What Actually Matters
Aug 25, 2026
Cybersecurity
SimplePractice vs TherapyNotes vs TheraNest: The IT and Security Side
Aug 25, 2026
Case Studies
The Phishing Attack That Beat MFA
Aug 25, 2026

Related posts

Digital Business Card