Offboarding a clinician in under 10 minutes
A clinician resigns, finishes Friday, and three weeks later their account still works. In healthcare, that's not just sloppy — a live account for a departed workforce member is one of the most common findings in OCR investigations, and disgruntled-insider access is a top cause of avoidable breaches.
Here's the sequence we run, in order, and why each step is where it is. With automation, the whole list takes under ten minutes; manually, budget an hour and a checklist.
The first five minutes
- Disable sign-in and revoke all active sessions — this kills phone and browser sessions immediately, not just future logins.
- Reset the account password (belt and braces for any cached credential).
- Remove the account from all security and distribution groups — this is what actually cuts EHR, file, and mailbox access in a role-based setup.
- Block or wipe managed devices; for BYOD, revoke the enrollment and app access.
The next five minutes
- Convert the mailbox to a shared mailbox (keeps mail history without a license) and forward new mail to a supervisor for 30–90 days.
- Transfer OneDrive ownership to their manager before the retention clock deletes it.
- Reclaim the license — real money back every month.
- Log all of it: who ran the offboarding, when, and what was touched.
The parts everyone forgets
- Third-party logins that don't go through M365 — e-prescribing, payer portals, lab systems. Keep a per-role app inventory so the checklist writes itself.
- Voicemail and phone system extensions.
- Door codes and alarm codes if your facility ties them to individuals.
- Scheduled reports or automations running under the departing user's account — these break silently weeks later.
Make it a workflow, not a memory
The difference between practices that offboard well and those that don't isn't diligence — it's whether offboarding is a form someone fills in or a list someone remembers. In ClinicOps, offboarding is a one-click automation: HR submits the name and last day, the sequence above executes, and the audit log writes itself.