Checklist · 6 pages
Employee Offboarding & Access Review Checklist for Dental Practices
A same-day checklist for removing a departing hygienist, associate, or front-desk employee's access to every system that touches patient data.
Dental practices lose staff more often than most small businesses. Hygienists move between offices for a better chair or a better schedule, associates rotate through on their way to an ownership position elsewhere, and front desk and temp coverage turns over even faster. Every one of those departures leaves behind a login: to the practice management system, to imaging software, to email, to the building itself.
Orphaned accounts, logins that stayed active after the person who used them left, are one of the most common findings in a HIPAA gap assessment and one of the most common ways a practice ends up notifying patients of a breach. Nobody decides to leave an ex-employee's access open. It happens because offboarding is handled informally, a week late, or only partially, while the practice is already short-staffed and focused on covering the schedule.
This checklist turns offboarding into a same-day, repeatable process, and adds a quarterly review to catch anything that slipped through. Use it every time someone leaves, and again each quarter against your full staff roster.
Same-day offboarding steps
Everything in this section happens the day someone leaves, whether that departure was planned or immediate. "By end of week" is not same-day, and the gap in between is exactly when access gets misused.
"End of week" is not disabled A login that stays active until someone gets around to disabling it is, for every practical purpose, not disabled at all. The gap between a person's last shift and the moment their access is actually cut off is exactly when a credential is most likely to be misused, out of frustration, out of habit, or by someone else entirely who still had it written down. Same-day is not the aspirational standard here. It is the only standard that closes the gap.
- PMS login disabled immediately, not scheduled for end of week or end of pay period The single most common gap. A departing employee's practice management system account should be disabled before they leave the building, not whenever someone gets around to it.
- Email and calendar access disabled Includes webmail and any mobile mail app still signed in on a personal phone. A live inbox after departure can expose patient correspondence and appointment details.
- Remote access and VPN credentials revoked If the practice allows remote login for charting, billing, or after-hours work, that credential is a full backdoor into the network if it is left active.
- Keys, badges, and practice-owned devices collected Laptops, tablets, pagers, and any loaner equipment. Log what was returned and by whom, so there is a record if something is missing.
- Removed from group texting, Slack, or other staff communication apps Staff coordination often happens outside the PMS entirely, in a group text or a messaging app. Those threads can carry scheduling and patient details and are easy to forget when offboarding.
- Removed from any shared clinical alert or paging system On-call rotations, lab result alerts, or emergency notification lists sometimes live in a separate tool from the PMS and get missed during a standard offboarding pass.
PMS & clinical software access
The practice management system is usually handled on day one. The software around it, imaging, e- prescribing, labs, referrals, is where access quietly survives.
- PMS user account disabled, not deleted Disabling preserves the audit trail of who did what while the account was active, which you may need later. Deleting the account can erase that history along with the login.
- Imaging or radiography software access revoked Digital X-ray and imaging systems frequently run on their own login, separate from the PMS, and get overlooked because of it.
- e-Prescribing credentials handled per state and DEA requirements Clinical staff with prescribing or EPCS credentials need that access formally deactivated through the prescribing platform and any required state reporting, not just a disabled PMS login.
- Lab portal or referral system access removed Outside lab and specialist referral portals are often set up individually per staff member and are easy to miss when they sit outside the practice's core system.
- Access to insurance or eligibility verification portals revoked Front desk staff commonly hold individual logins to payer portals for benefits and eligibility checks. Those need to be closed out along with everything else.
- Saved sessions on personal devices or browsers signed out A personal phone or home computer with a saved, still-logged-in session can outlive the account disable if nobody thinks to check for it.
Email, phone, and shared accounts
The accounts most likely to be shared, forwarded, or half-configured, and the ones an outgoing employee is most likely to still know the password to.
- Personal email forwarding or auto-reply set up if needed If patients or referring offices email the departing employee directly, route that mail somewhere it will actually be seen rather than leaving it to accumulate in a disabled inbox.
- Shared or generic account passwords changed if the departing employee knew them A front-desk or scheduling login used by multiple people cannot simply be disabled for one person. Change the password and redistribute it to everyone who still needs it.
- Phone system extension reassigned or deactivated Includes voicemail. An active extension still ringing to a former employee's voicemail is a small thing that looks unprofessional and can miss patient calls.
- Personal devices with practice email removed, MDM wipe applied if available If the practice email profile was ever installed on a personal phone, remove it. Where mobile device management is in place, wipe the practice data remotely rather than relying on the employee to delete it themselves.
- Access to the patient text or appointment reminder platform revoked Scheduling and reminder tools often issue their own staff logins, separate from the PMS, with visibility into patient contact information.
- Social media or online review management access revoked, if held Staff who managed the practice's Google Business Profile, Facebook page, or review responses should have that access transferred or removed so the practice's public presence stays under its own control.
Physical access
Digital access gets most of the attention. A practice that disables every login but leaves a shared alarm code unchanged has not finished the job.
- Building or alarm code changed if it was shared knowledge A code known to multiple staff cannot be tied to one person. Treat it the same as a shared password and rotate it.
- Keys returned and logged Note which keys were issued to the departing employee and confirm each one came back, rather than trusting memory.
- Badge or fob deactivated Deactivate in the access control system itself, not just by collecting the physical badge. A lost or unreturned badge should be deactivated regardless.
- Safe or petty cash access updated Combinations, cash box keys, or safe app credentials known to the departing employee should be changed, not just noted as "someone who used to know it."
- Loaner equipment returned and inventoried Laptops, tablets, intraoral cameras, or pagers issued for take-home or after-hours use should be accounted for individually, not lumped in with a general "turned in their stuff" assumption.
- Supply cabinet or medication storage codes changed if applicable Where controlled substances or high-value supplies are stored behind a shared code, treat that code the same as any other shared credential.
Quarterly access review
Same-day offboarding catches the departures you know about. A quarterly review catches everything that slipped through anyway, and there is always something.
Set a recurring calendar reminder, once per quarter, to run this review against your actual current staff roster rather than against memory. This takes most practices under an hour and is the single cheapest control on this entire checklist.
- Full user list in the PMS and other core systems reviewed against the current staff roster Pull the actual account list from each system and compare it name by name to who is currently employed. Anyone on the account list who is not on the roster is a finding.
- Confirmed no shared or generic logins have crept back in Shared logins tend to reappear over time, usually because they are the path of least resistance during a busy week. Check for them explicitly rather than assuming the earlier fix held.
- Confirmed departed-employee accounts were actually disabled, not just intended to be Same-day offboarding is a process, and processes get skipped when the practice is short- staffed. Verify the account status directly rather than trusting that the step happened.
- Vendor and contractor accounts reviewed for any that should have expired Temp hygienists, IT contractors, and seasonal coverage often get access set up for a defined engagement that has since ended. Those accounts are easy to forget because no one "offboarded" in the usual sense.
- Multi-factor authentication confirmed enforced on every remaining active account A quarterly review is also the right moment to catch any account that was created or restored without MFA turned on.
Want the printable version?
Get the full checklist as a free PDF
Everything on this page, formatted to print or save, delivered straight to your inbox. No sales call required.
Download the free PDF