← All posts
Filed in / hipaa · compliance · small-business

HIPAA Employee Offboarding Checklist: Email, Files, Chat, and Shared Access

In this piece
  1. 01 Assign the handoff before the departure
  2. 02 Use an action and evidence checklist
  3. 03 Check access that does not use the main login
  4. 04 Preserve records without preserving the person’s access
  5. 05 Verify the result and close exceptions
  6. 06 Rehearse the process during a pilot

Healthcare offboarding should verify that access ends and that the successor can continue the work. A departing employee’s email account is only one checkpoint. Review shared folders, delegated mailboxes, connected apps, active sessions, and downloaded files.

HHS advises healthcare organizations to end former workforce members’ access to PHI, including access through cloud services and personal devices where permitted. Its guidance on termination procedures also recommends confirming that the procedures work. Use the checklist below as a practical starting point for your environment.

Assign the handoff before the departure

Record who is leaving, which role is ending, and the effective access cutoff. Include contractors and temporary staff in the same process. A role change may require removing old permissions even when the person remains employed.

Identify an owner for the overall handoff. In a small practice, one person may coordinate HR, the IT provider, and the privacy or security official. Each action still needs an accountable owner and completion evidence.

Set the cutoff around the actual end of authorization. HHS recommends terminating electronic and physical access as soon as possible. See the HHS termination checklist.

Use an action and evidence checklist

Adapt this suggested operating checklist to your systems, agreements, and record requirements.

Owner Action Evidence to keep
Manager Confirm departure time and successor Approved handoff record
IT administrator Disable identity and direct application access Account status and completion time
IT administrator Revoke active sessions and access tokens where supported Revocation result and any exceptions
Mail administrator Review delegation, forwarding, and shared inbox access Updated access list
File owner Review direct shares, groups, and external invitations Permission changes and verification
Chat administrator Remove memberships and review connected apps Membership and integration review
Device owner Recover equipment and address permitted local PHI copies Device receipt or documented disposition
Records owner Preserve required content and assign a successor Preservation decision and access check

Also complete the organization’s physical access process, including keys, badges, and remote access equipment. HHS includes both physical and electronic access in its offboarding guidance.

If this checklist spans several tools and owners, request a healthcare pilot with an offboarding exercise to evaluate the handoff in IRONKEEP’s private beta workspace. Use a fictional staff account and a synthetic record to scope the test; review BAA needs before introducing ePHI.

Check access that does not use the main login

Ask each application owner whether disabling the identity provider also disables local credentials, mobile sessions, and app-specific tokens. Do not assume every integration follows the same lifecycle.

Look for a contractor’s separate account at a client organization, a personal address invited to a folder, or a service connection authorized under the departing person’s identity. Arrange a supported transfer or replacement for necessary integrations. Do not preserve a former employee’s login simply because an automated process depends on it.

For shared secrets the person knew, determine which need rotation and coordinate any dependent services. Record unresolved items with an owner instead of marking the entire checklist complete.

Preserve records without preserving the person’s access

Suspending access and deleting content are separate decisions. Before deleting a mailbox or user-owned files, have the records owner check the applicable schedule and any preservation instructions. The HIPAA retention guide explains why a single retention setting cannot answer every records question.

For example, a billing coordinator may own the folder used for an ongoing client request. Give the successor authorized access and test it before removing an account in a way that could lose the folder. Keep the handoff limited to the successor’s actual work.

Verify the result and close exceptions

Have an administrator confirm the former account is disabled and review available access evidence around the cutoff. Verify that the successor can perform the necessary work. Use synthetic accounts for rehearsal.

Log the result, reviewer, and any remaining device or vendor follow-up. An unreturned laptop or independently managed client account is an open item, even if the email account is already closed.

Rehearse the process during a pilot

Bring your ePHI inventory, a sample role, and a successor’s access needs to the evaluation. Keep the completed action-and-evidence checklist so your team can compare the result with its current process. A successful rehearsal should show both that access ended and that the successor can continue the work.

Healthcare · Private beta

Scope your healthcare workspace.

Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.

Request a healthcare pilot