top of page

When an Employee Leaves Your Medical Practice, Does Their Access Leave Too?

9 hours ago
2 min read

Employee turnover is a normal part of running a medical practice.



But every time someone joins, changes roles, or leaves your organization, there is an important technology question that needs to be addressed:


Who has access to what?


Employees may have access to email, Microsoft 365, EHR systems, shared files, cloud applications, remote access, practice management software, and other systems containing sensitive information.


If those accounts and permissions aren't properly managed, yesterday's employee could become today's cybersecurity risk.


Offboarding Is More Than Deleting an Email Account

When an employee leaves, disabling their email account is only one part of the process.

Their access may exist across multiple systems, applications, devices, and third-party platforms. Credentials may also have been shared between employees—a practice that can make determining who has access even more difficult.


A consistent offboarding process should help ensure access is removed promptly and that company-owned devices, accounts, files, and credentials are properly addressed.

For medical practices, this is particularly important when systems contain sensitive patient or business information.


The Same Problem Can Happen When Employees Change Roles

Access shouldn't simply accumulate over time.


An employee who moves from one position to another may no longer need access to every system or folder they previously used.


A good principle is straightforward:


Employees should have access to what they need to do their jobs—not everything they might possibly need.


Periodically reviewing permissions can help identify unnecessary access before it becomes a larger security concern.


Good Onboarding Matters Too

Access management isn't only about employees leaving.


New employees need the right technology from day one.


Their workstation should be ready, required accounts should be created, appropriate permissions should be assigned, security protections should be active, and multi-factor authentication should be configured where appropriate.


When IT is involved before an employee's first day, onboarding can be smoother for both the new hire and practice management.


Instead of spending the morning figuring out passwords, computers, and application access, the employee can get to work.


Your IT Provider Should Help Manage the Entire Account Lifecycle

Onboarding, role changes, and offboarding shouldn't depend on someone remembering a long list of individual tasks every time.


Your IT provider should help establish a repeatable process for managing accounts, devices, permissions, and security as employees move through the organization.


At CyberSphere Solutions, we help medical practices proactively manage their technology and cybersecurity—from user accounts and Microsoft 365 to networks, endpoints, backups, EHR support, and HIPAA-focused IT safeguards.


The goal is to make sure the right people have the right access at the right time.


Who Still Has Access to Your Practice?

If you aren't confident that former employees have been fully removed or that current permissions reflect what employees actually need, it may be time for a review.


Schedule a Complimentary IT & Cybersecurity Assessment with CyberSphere Solutions.


We'll help identify potential technology and security gaps and opportunities to strengthen the way your practice manages its IT environment.


Call (305) 518-1788 to schedule your complimentary assessment.

Comments


bottom of page