🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by role

HIPAA offboarding checklist: removing access for staff, providers, contractors and vendors

HIPAA offboarding means ending a person's or vendor's access to patient information when the relationship ends: disable every system login on the last day, recover devices, keys and codes, confirm no PHI remains on personal devices, and for vendors, get PHI returned or destroyed under the BAA and take back every account. The Security Rule requires termination procedures, and OCR has settled cases where former employees kept access. The fastest way to do it right is to keep an access register from the day someone starts.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • The Security Rule asks for procedures to terminate access when employment or another arrangement ends (45 CFR 164.308(a)(3)(ii)(C)).
  • For vendors, the BAA must require return or destruction of PHI at termination, or continued protection where that is not feasible (164.504(e)(2)(ii)(J)).
  • Remove access on the last day; for involuntary departures, at or before the exit conversation.
  • Offboarding works only if Onboard and Access kept an access register: every system, every account, every device.
  • Keep each completed checklist with your HIPAA records for six years (164.530(j)).
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Why it matters

Offboarding is where small practices get caught

Short answer: people leave in a hurry, vendors are replaced without ceremony, and nobody owns the list of what each one could reach. Months later, an old login still works.

OCR case: a former employee's calendar access. Pagosa Springs Medical Center in Colorado paid $111,400 after a former employee kept remote access to a web-based scheduling calendar holding hundreds of patients' ePHI, and the practice had no BAA with the calendar vendor. The corrective plan required updated security management and BAA policies and workforce training.
OCR case: a login used for a year. Memorial Healthcare System in Florida paid $5.5 million after a former affiliated-office employee's credentials were used to access ePHI daily for about a year without detection. OCR cited failures to terminate users' access and to review system activity.

This page is the Stage 4 companion to our four-stage HIPAA framework. It works for every role: front desk, providers, managers, billing, marketing, contractors and vendors.

The four stages

How the first three stages make offboarding possible

Short answer: you cannot remove access you do not know about. Clean exits are built at the start.

Stage 1 · Onboard: start the access register

When someone joins or a vendor is signed, open a record listing every account created, every device issued, every key or code handed over, and for vendors, the BAA date, subcontractors and data held. Set an end date at creation for temporary staff, students and locums.

Stage 2 · Access: keep it current

Every new system or permission goes on the register. Named logins only (unique user IDs are required under 164.312(a)(2)(i)), so you know exactly whose access to remove. Shared logins mean changing a password for everyone when one person leaves, which is why they rarely get changed.

Stage 3 · Operate: review it

Quarterly, compare each system's user list with your staff list and vendor register. Remove anyone who should not be there. Review EHR access logs regularly (164.312(b), 164.308(a)(1)(ii)(D)), which catches leftover access if it is ever used.

Stage 4 · Offboard: run the checklist

On the last day, work through the register line by line, using the checklist below. The Security Rule requires termination procedures (164.308(a)(3)(ii)(C)); the register and checklist are how you prove you have them.

Checklist

Printable HIPAA offboarding checklist

Name: ____________________   Role: ____________________   Last day: ____________   Completed by: ____________________

All staff: systems

  • EHR and practice management accounts disabled
  • Online booking and scheduling access removed
  • Phone system login, voicemail box and call-recording access removed
  • Patient texting and email platform accounts removed
  • Practice email disabled; forwarding to personal email blocked; mailbox delegated to manager
  • Shared inboxes, cloud drives and file shares removed
  • Payment terminal, payer portal and clearinghouse logins removed
  • Shared passwords they knew rotated (Wi-Fi, door codes, shared accounts)
  • Audit log checked for unusual access in the final weeks

All staff: devices and premises

  • Practice laptop, phone, tablet and tokens returned
  • Personal phone signed out of practice apps remotely; PHI deletion confirmed in writing
  • Keys, badge and parking pass collected
  • Alarm and door codes changed
  • Paper records or notes at home returned or shredded
  • Reminder of continuing confidentiality obligations given and acknowledged

Providers (add)

  • E-prescribing credentials and imaging or lab portal access removed
  • Clinical photo app and secure messaging accounts removed
  • Patient photos deleted from personal devices and personal cloud backups; signed confirmation
  • Patient communication about the departure agreed with the practice; no patient lists taken

Marketing staff (add)

  • Removed from ad, analytics, Google Business Profile, social, email, CRM, review and website accounts
  • Ownership transferred for any account under a personal login
  • API keys and integrations they created reviewed or revoked
  • Local exports of lead or patient data deleted

Practice manager or owner (add)

  • Privacy official and security official roles reassigned in writing (164.530(a), 164.308(a)(2))
  • Admin credentials, break-glass account and vendor register handed over
  • All admin and service passwords rotated after handover
  • Open incidents, complaints and risk management tasks handed over

Contractors, locums and students (add)

  • Accounts expired on the end date set at creation; confirmed disabled
  • Any devices or badges returned
  • PHI on personal devices deleted; confirmation received

Vendors and agencies

  • Data exported: records, lead history, call logs, reviews, creative assets
  • Vendor users removed from every practice system and account
  • API keys, integrations and remote-access tools revoked or removed
  • Ownership confirmed or transferred: ad accounts, analytics, domains, hosting, call-tracking numbers, social pages
  • Written return-or-destruction confirmation for PHI, including subcontractors (164.504(e)(2)(ii)(J))
  • Where destruction is not feasible, written statement of what remains and how it stays protected
  • Vendor register updated; BAA and exit records filed

Cleaning and facilities

  • Keys and alarm codes collected or changed
  • Shred-bin and records-room access reviewed

Close out

  • Checklist signed by the security official and filed for six years (164.530(j))
Timing and mistakes

Timing, common misses and what to do if you find leftover access

Timing

  • Voluntary departure: plan the checklist during the notice period; disable accounts at the end of the last shift.
  • Involuntary departure: disable accounts at or just before the conversation; collect devices in the meeting.
  • Role change: treat it as a partial offboarding. Remove what the old role needed and the new one does not.
  • Vendor change: overlap the old and new vendor briefly for data transfer, then cut off the old one on a set date.

Common misses

Often missedWhyFix
Mobile appsDisabling the desktop login does not always end a mobile session.Revoke sessions and remote sign-out in each app.
Shared loginsNo one wants to reset a password everyone uses.Replace with named accounts; rotate now.
Third-party tools signed up ad hocNot on the register, often no BAA.Ask the leaver to list every tool they used; check expense reports.
Ad and analytics ownershipAccounts created under an employee's or agency's login.Ownership in the practice's name from day one.
Personal-device PHIPhotos and texts outside managed apps.Signed deletion confirmation; tighter device policy.

If you find leftover access

Disable it immediately. Then check the audit logs for any activity after the departure date. If the account was used to view or take PHI, treat it as a possible breach: run the four-factor risk assessment (164.402), and if notification is required, notify patients within 60 days of discovery (164.404). Document what you found even if nothing was accessed, and tighten the step that failed. More detail on breach decisions is in HIPAA for practice managers.

Med spa owners can find the marketing side on our med spa marketing page, in the med spa marketing statistics for 2026 and the med spa Google presence report. State advertising rules: state medical board guide or the Texas guide. In-house marketers: HIPAA for marketing teams. Browse all US guides or book a call.

Sources

Sources

Keep reading

Related pages from the US team

HIPAA compliance by role

The full four-stage framework and the roles-by-stages matrix.

HIPAA for practice managers

Access reviews, vendor register and breach decisions.

What to require from agencies and vendors

Exit terms to write into the BAA before you start.

HIPAA for front desk staff

The four stages for coordinators.

HIPAA for providers

Photos, devices and social media rules for clinicians.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

How soon must we remove a former employee's access under HIPAA?

HIPAA does not set a number of hours. The Security Rule requires procedures for terminating access when employment ends, and OCR has penalized organizations whose former staff kept access. Remove access on the last working day, and for involuntary terminations disable accounts at or just before the exit meeting.

Do we need to get patient photos off a departing provider's phone?

Yes. Patient photos are PHI. Your policy should require providers to keep photos inside approved apps, and offboarding should include remote sign-out of those apps, deletion of any PHI on personal devices and a signed confirmation from the provider.

What should we get from a vendor when we end the contract?

An export of your data, written confirmation that the vendor and its subcontractors have returned or destroyed your PHI (or a statement of what cannot be destroyed and how it stays protected), removal of the vendor's users from your systems, and ownership of any accounts such as ad, analytics, domain, website and call-tracking numbers.

Is forgetting to remove access a breach?

Not automatically. Leftover access becomes a breach question if the person actually uses it to view or take PHI, or if you cannot show they did not. Check the audit logs for any activity after the departure date and run the four-factor breach risk assessment if you find any.

Who should own the offboarding checklist?

The security official, usually the practice manager, with sign-off from whoever administers each system. When the practice manager is the person leaving, the owner or a designated replacement runs the checklist, including transferring the privacy and security official roles.

How long do we keep offboarding records?

Six years from creation or from when they were last in effect, under HIPAA's documentation rule. Keep the completed checklist, signed device and PHI-deletion confirmations, and vendor return-or-destruction letters with your other HIPAA records.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Changing marketing agencies?

A 30-minute call with the Ichelon Consulting US team. We can help you check what your current agency holds and make sure every account is in your name. BAA signed before we start.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership