HIPAA offboarding checklist: removing access for staff, providers, contractors and vendors
HIPAA offboarding means ending a person's or vendor's access to patient information when the relationship ends: disable every system login on the last day, recover devices, keys and codes, confirm no PHI remains on personal devices, and for vendors, get PHI returned or destroyed under the BAA and take back every account. The Security Rule requires termination procedures, and OCR has settled cases where former employees kept access. The fastest way to do it right is to keep an access register from the day someone starts.
- The Security Rule asks for procedures to terminate access when employment or another arrangement ends (45 CFR 164.308(a)(3)(ii)(C)).
- For vendors, the BAA must require return or destruction of PHI at termination, or continued protection where that is not feasible (164.504(e)(2)(ii)(J)).
- Remove access on the last day; for involuntary departures, at or before the exit conversation.
- Offboarding works only if Onboard and Access kept an access register: every system, every account, every device.
- Keep each completed checklist with your HIPAA records for six years (164.530(j)).
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Offboarding is where small practices get caught
Short answer: people leave in a hurry, vendors are replaced without ceremony, and nobody owns the list of what each one could reach. Months later, an old login still works.
This page is the Stage 4 companion to our four-stage HIPAA framework. It works for every role: front desk, providers, managers, billing, marketing, contractors and vendors.
How the first three stages make offboarding possible
Short answer: you cannot remove access you do not know about. Clean exits are built at the start.
Stage 1 · Onboard: start the access register
When someone joins or a vendor is signed, open a record listing every account created, every device issued, every key or code handed over, and for vendors, the BAA date, subcontractors and data held. Set an end date at creation for temporary staff, students and locums.
Stage 2 · Access: keep it current
Every new system or permission goes on the register. Named logins only (unique user IDs are required under 164.312(a)(2)(i)), so you know exactly whose access to remove. Shared logins mean changing a password for everyone when one person leaves, which is why they rarely get changed.
Stage 3 · Operate: review it
Quarterly, compare each system's user list with your staff list and vendor register. Remove anyone who should not be there. Review EHR access logs regularly (164.312(b), 164.308(a)(1)(ii)(D)), which catches leftover access if it is ever used.
Stage 4 · Offboard: run the checklist
On the last day, work through the register line by line, using the checklist below. The Security Rule requires termination procedures (164.308(a)(3)(ii)(C)); the register and checklist are how you prove you have them.
Printable HIPAA offboarding checklist
Name: ____________________ Role: ____________________ Last day: ____________ Completed by: ____________________
All staff: systems
- EHR and practice management accounts disabled
- Online booking and scheduling access removed
- Phone system login, voicemail box and call-recording access removed
- Patient texting and email platform accounts removed
- Practice email disabled; forwarding to personal email blocked; mailbox delegated to manager
- Shared inboxes, cloud drives and file shares removed
- Payment terminal, payer portal and clearinghouse logins removed
- Shared passwords they knew rotated (Wi-Fi, door codes, shared accounts)
- Audit log checked for unusual access in the final weeks
All staff: devices and premises
- Practice laptop, phone, tablet and tokens returned
- Personal phone signed out of practice apps remotely; PHI deletion confirmed in writing
- Keys, badge and parking pass collected
- Alarm and door codes changed
- Paper records or notes at home returned or shredded
- Reminder of continuing confidentiality obligations given and acknowledged
Providers (add)
- E-prescribing credentials and imaging or lab portal access removed
- Clinical photo app and secure messaging accounts removed
- Patient photos deleted from personal devices and personal cloud backups; signed confirmation
- Patient communication about the departure agreed with the practice; no patient lists taken
Marketing staff (add)
- Removed from ad, analytics, Google Business Profile, social, email, CRM, review and website accounts
- Ownership transferred for any account under a personal login
- API keys and integrations they created reviewed or revoked
- Local exports of lead or patient data deleted
Practice manager or owner (add)
- Privacy official and security official roles reassigned in writing (164.530(a), 164.308(a)(2))
- Admin credentials, break-glass account and vendor register handed over
- All admin and service passwords rotated after handover
- Open incidents, complaints and risk management tasks handed over
Contractors, locums and students (add)
- Accounts expired on the end date set at creation; confirmed disabled
- Any devices or badges returned
- PHI on personal devices deleted; confirmation received
Vendors and agencies
- Data exported: records, lead history, call logs, reviews, creative assets
- Vendor users removed from every practice system and account
- API keys, integrations and remote-access tools revoked or removed
- Ownership confirmed or transferred: ad accounts, analytics, domains, hosting, call-tracking numbers, social pages
- Written return-or-destruction confirmation for PHI, including subcontractors (164.504(e)(2)(ii)(J))
- Where destruction is not feasible, written statement of what remains and how it stays protected
- Vendor register updated; BAA and exit records filed
Cleaning and facilities
- Keys and alarm codes collected or changed
- Shred-bin and records-room access reviewed
Close out
- Checklist signed by the security official and filed for six years (164.530(j))
Timing, common misses and what to do if you find leftover access
Timing
- Voluntary departure: plan the checklist during the notice period; disable accounts at the end of the last shift.
- Involuntary departure: disable accounts at or just before the conversation; collect devices in the meeting.
- Role change: treat it as a partial offboarding. Remove what the old role needed and the new one does not.
- Vendor change: overlap the old and new vendor briefly for data transfer, then cut off the old one on a set date.
Common misses
| Often missed | Why | Fix |
|---|---|---|
| Mobile apps | Disabling the desktop login does not always end a mobile session. | Revoke sessions and remote sign-out in each app. |
| Shared logins | No one wants to reset a password everyone uses. | Replace with named accounts; rotate now. |
| Third-party tools signed up ad hoc | Not on the register, often no BAA. | Ask the leaver to list every tool they used; check expense reports. |
| Ad and analytics ownership | Accounts created under an employee's or agency's login. | Ownership in the practice's name from day one. |
| Personal-device PHI | Photos and texts outside managed apps. | Signed deletion confirmation; tighter device policy. |
If you find leftover access
Disable it immediately. Then check the audit logs for any activity after the departure date. If the account was used to view or take PHI, treat it as a possible breach: run the four-factor risk assessment (164.402), and if notification is required, notify patients within 60 days of discovery (164.404). Document what you found even if nothing was accessed, and tighten the step that failed. More detail on breach decisions is in HIPAA for practice managers.
Med spa owners can find the marketing side on our med spa marketing page, in the med spa marketing statistics for 2026 and the med spa Google presence report. State advertising rules: state medical board guide or the Texas guide. In-house marketers: HIPAA for marketing teams. Browse all US guides or book a call.
Sources
- 45 CFR 164.308 (termination procedures, information system activity review, security official): law.cornell.edu/cfr/text/45/164.308
- 45 CFR 164.312 (unique user identification, audit controls): law.cornell.edu/cfr/text/45/164.312
- 45 CFR 164.504(e)(2)(ii)(J) (return or destruction of PHI at BAA termination): law.cornell.edu/cfr/text/45/164.504
- 45 CFR 164.530 (privacy official, documentation and six-year retention): law.cornell.edu/cfr/text/45/164.530
- 45 CFR 164.402 and 164.404 (breach risk assessment and notification): law.cornell.edu/cfr/text/45/164.402
- OCR, Pagosa Springs Medical Center: hhs.gov
- OCR, Memorial Healthcare System: hhs.gov
Related pages from the US team
HIPAA compliance by role
The full four-stage framework and the roles-by-stages matrix.
HIPAA for practice managers
Access reviews, vendor register and breach decisions.
What to require from agencies and vendors
Exit terms to write into the BAA before you start.
HIPAA for front desk staff
The four stages for coordinators.
HIPAA for providers
Photos, devices and social media rules for clinicians.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
How soon must we remove a former employee's access under HIPAA?
HIPAA does not set a number of hours. The Security Rule requires procedures for terminating access when employment ends, and OCR has penalized organizations whose former staff kept access. Remove access on the last working day, and for involuntary terminations disable accounts at or just before the exit meeting.
Do we need to get patient photos off a departing provider's phone?
Yes. Patient photos are PHI. Your policy should require providers to keep photos inside approved apps, and offboarding should include remote sign-out of those apps, deletion of any PHI on personal devices and a signed confirmation from the provider.
What should we get from a vendor when we end the contract?
An export of your data, written confirmation that the vendor and its subcontractors have returned or destroyed your PHI (or a statement of what cannot be destroyed and how it stays protected), removal of the vendor's users from your systems, and ownership of any accounts such as ad, analytics, domain, website and call-tracking numbers.
Is forgetting to remove access a breach?
Not automatically. Leftover access becomes a breach question if the person actually uses it to view or take PHI, or if you cannot show they did not. Check the audit logs for any activity after the departure date and run the four-factor breach risk assessment if you find any.
Who should own the offboarding checklist?
The security official, usually the practice manager, with sign-off from whoever administers each system. When the practice manager is the person leaving, the owner or a designated replacement runs the checklist, including transferring the privacy and security official roles.
How long do we keep offboarding records?
Six years from creation or from when they were last in effect, under HIPAA's documentation rule. Keep the completed checklist, signed device and PHI-deletion confirmations, and vendor return-or-destruction letters with your other HIPAA records.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Changing marketing agencies?
A 30-minute call with the Ichelon Consulting US team. We can help you check what your current agency holds and make sure every account is in your name. BAA signed before we start.