When someone leaves a clinic, the security task is larger than disabling the main application login. The person may own appointment queues, shared inboxes, prescription templates, cloud folders, messaging sessions, building keys, vendor portals, and unresolved patient follow-ups. A rushed departure can leave both unauthorized access and abandoned care work.
Good offboarding begins as soon as the departure is confirmed, assigns exact times for access changes, and separates business continuity from evidence preservation. Voluntary, involuntary, contractor, and temporary-leave scenarios may need different timing, but every case should finish with one accountable sign-off rather than a collection of assumed actions.
Build the workflow in five deliberate steps
1. Classify the departure and timing
Record last working time, manager, role, clinics, risk level, and whether access should end immediately or at shift completion. Coordinate HR, operations, IT, and the clinical lead discreetly. Do not rely on a calendar date when a user can still sign in during the final evening.
2. Build an account and asset inventory
Start from the role's standard access list, then add exceptions: administrator rights, email, messaging, storage, payroll, scheduling, remote access, integrations, vendor support, physical keys, cards, tokens, laptops, and phones. Review password-manager and identity-provider assignments so unknown secondary accounts do not survive.
3. Transfer work before deleting anything
Reassign upcoming appointments, unsigned notes, results, prescriptions awaiting review, inbox conversations, tasks, reports, and vendor relationships. Preserve required records and manager access to business material without taking over the departing person's private credentials. Notify patients only where continuity requires it and use approved wording.
4. Disable sessions and recover control
Suspend individual accounts, revoke active sessions and tokens, remove groups and forwarding, rotate shared secrets the person knew, recover devices and keys, and remove remote-management profiles as policy requires. Keep audit history linked to the former user rather than deleting the identity record and erasing attribution.
5. Verify and close independently
Have a second person compare completed actions with the inventory, test that access is blocked, confirm assets and records are accounted for, and document exceptions. Review recent privileged or bulk activity when risk warrants it. Set follow-up dates for delayed actions such as vendor deletion or device return.
A practical 30-day rollout
Start with observation, not configuration. During the first week, follow the work as it happens and record who makes each decision, which information they need, and where they wait or improvise. In week two, agree on one written version of the process and test it with a small group. Use week three to correct permissions, templates, ownership, and exceptions. In week four, train the wider team, publish the final checklist, and schedule the first review. A controlled rollout creates evidence; an overnight announcement creates workarounds.
Give one named owner authority to close gaps during the trial. The owner should keep a short decision log: what changed, why it changed, and what signal will show whether it worked. That log prevents the same debate from restarting every month and gives new staff a reliable explanation of the workflow.
Operational checklist
- Last working time, departure type, manager, and risk level are recorded.
- Clinical, administrative, vendor, physical, and remote access are inventoried.
- Appointments, results, notes, messages, and tasks have named new owners.
- Active sessions, tokens, app passwords, and forwarding rules are revoked.
- Known shared secrets are rotated without creating new shared accounts.
- Devices, keys, cards, documents, and clinic-owned data are recovered.
- The former identity is disabled while its audit history is retained.
- A second reviewer verifies closure and tracks remaining exceptions.
Measure whether the change is working
Choose a small baseline before launch and compare it at 14 and 30 days. Do not reward activity alone; measure whether the workflow became safer, faster, clearer, or easier to audit. The following signals are specific enough for a clinic manager to review without building a separate reporting project.
- Time from approved departure to access suspension across all systems.
- Offboarding cases completed with no unowned patient work.
- Assets and credentials unresolved after the final working day.
- Former-user authentication attempts or active sessions after closure.
Four failure modes to prevent
- Deleting the user instead of disabling access. Deletion can damage the audit trail and obscure who performed earlier actions.
- Closing only the clinic application. Email, storage, messaging, vendors, and physical access may remain open.
- Forgetting continuity. Results and follow-ups without a new owner create patient risk even when security tasks succeed.
- Scheduling suspension for midnight. Exact departure timing should reflect the real final shift and risk decision.
Where clinic software should help
Software should make the agreed process easier to follow and harder to bypass. It should provide clear ownership, role-aware access, timestamps, searchable history, and a reliable handoff to the next person. It should not hide policy behind a button or force staff to maintain a second spreadsheet. See how MyClinic supports this work in accountable user and access history, then adapt the workflow to the clinic's actual roles and local obligations.
This article belongs to our Security, Compliance & Data library. Two useful next reads are:
- Designing healthcare role-based access
- Reviewing clinic audit logs
- Read the established cluster guide
Put the policy into daily practice
Turn this checklist into role-specific templates for doctors, reception, managers, contractors, and support staff. Trigger them from the same approved departure event and keep one closure record. Speed matters, but complete transfer and independent verification make the process defensible.
Frequently Asked Questions
Quick answers to questions you may have.
Should a former employee account be deleted?
When should access be removed?
What patient work needs transfer?
Who signs off offboarding?
Start running a calmer clinic today.
Set up takes less than an hour. Your first prescription prints straight onto your pre-printed paper — we’ll help you calibrate.