HIPAA Employee Offboarding at Home Health Agencies: The Complete Security Checklist
HIPAA

HIPAA Employee Offboarding at Home Health Agencies: The Complete Security Checklist

3 min read
SF
Obi Ibeto

Of all the security compliance failures I encounter at home health agencies, the persistence of former employee access is simultaneously the most common, the most preventable, and the most likely…

Of all the security compliance failures I encounter at home health agencies, the persistence of former employee access is simultaneously the most common, the most preventable, and the most likely to result in a breach. I have assessed agencies where clinical staff who left six months ago still had active EHR logins. Billing coordinators whose employment ended after a termination-for-cause event who retained full billing system access for weeks. A nurse who resigned following a patient complaint, whose EHR account remained active while an investigation was conducted — and who accessed the complaining patient's record twelve days after her resignation. Each of these is a documented HIPAA violation. Each was preventable with a functional offboarding process.

The HIPAA Security Rule requires covered entities to implement procedures for terminating access to ePHI when an employment relationship ends. It does not specify a timeline for that termination — but OCR enforcement actions have consistently treated same-day termination as the expected standard for clinical and administrative staff who have regular ePHI access.

Why Offboarding Security Fails at Home Health Agencies

The failure mode is almost always the same: offboarding is treated as an HR process with a technology component rather than as a security process with an HR notification trigger. HR initiates the offboarding. The outgoing employee's manager completes the paperwork. Someone eventually remembers to notify IT. By the time the IT notification reaches the right person — who may be an external IT vendor, not a staff member — the departed employee has had access for days or weeks.

The second failure mode is incomplete deactivation: the HR system records the departure, the Microsoft 365 account is deactivated, but the EHR account — which is managed by a different administrator in a different system — is not deactivated because the EHR administrator was not on the notification list. Most home health agencies manage four to eight separate systems that grant access to patient information. Deactivating access in one or two of them while leaving others active is only marginally better than deactivating none of them.

The Complete Home Health Offboarding Security Checklist

Immediate Actions — Same Day as Departure

       Microsoft 365 or Google Workspace account: suspend immediately, revoke all active sessions, disable all access — do not delete the account until the retention period for email and file content is confirmed

       EHR account (primary platform): deactivate login, revoke all active sessions, set the account status to terminated in the audit log

       Scheduling platform (if separate from EHR): deactivate account

       Billing system (if separate from EHR): deactivate account

       MDM: remotely wipe the work container on any enrolled personal device; initiate full wipe on any agency-owned device that is not yet returned

       VPN access: revoke VPN credentials and remove from any VPN user group

       Multi-factor authentication: deactivate all registered MFA methods for the account to prevent re-authentication attempts

       Dark web monitoring: flag the departed employee's credentials for heightened monitoring for 60 days following departure — former employee credentials that appear on the dark web are a meaningful indicator of insider threat activity

Within 24 Hours

       Physical access: collect agency-issued keys, key cards, and access badges; deactivate any electronic access credentials for the office facility

       Agency-owned devices: confirm return and receipt of all agency-owned devices; verify device encryption and wipe any device with patient data before reassignment

       Personal device offboarding: confirm through MDM that the work container has been wiped from any personal device that was enrolled in the BYOD programme

       Shared credentials: if the departed employee had access to any shared credentials (shared email inboxes, shared scheduling accounts, shared vendor portal logins), rotate those credentials immediately

Within 5 Business Days

       Access review: run an access audit across all systems to confirm deactivation is complete — compare the current active user list in each system against the departed employee roster

       Documentation: record the offboarding in the access management log with the employee name, departure date, systems deactivated, date of each deactivation, and the staff member who performed each action

       Audit log review: review the departed employee's access activity in the EHR and other systems for the 30 days preceding departure for any anomalous access that should be investigated

ShieldForce clients receive automated offboarding checklists through our managed platform — triggered by notification from HR, with each step confirmed and logged automatically.

 

Protecting your home health agency does not have to be complicated. It has to be done — completely, correctly, and documented in a way that holds up when it matters. ShieldForce makes that possible for organisations without IT departments, without compliance staff, and without the budget of a hospital system. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore Home Healthcare Cybersecurity — shieldforce.io/home-healthcare

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#HIPAA#HIPAA Compliance#HIPAA audit#Compliance#Home Healthcare Security#Home Health#documentation
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.