What to Do If a Former Employee Still Has Remote EHR Access After Termination: Immediate Steps

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

What to Do If a Former Employee Still Has Remote EHR Access After Termination: Immediate Steps

Kevin Henry

Incident Response

September 01, 2026

6 minutes read
Share this article
What to Do If a Former Employee Still Has Remote EHR Access After Termination: Immediate Steps

Discovering that a former employee still has remote EHR access is an urgent risk to Protected Health Information and organizational trust. Your response must be fast, coordinated, and well-documented to contain exposure and meet regulatory obligations.

This guide outlines immediate actions, investigation steps, and prevention practices you can apply right now. Follow each section in order to strengthen Remote Access Security and demonstrate diligence if questions arise later.

Immediate Access Termination

Move first to halt all live connectivity. Prioritize speed, then verification.

  • Disable identity provider and EHR user accounts; force logouts and revoke active sessions and tokens.
  • Block VPN, remote desktop, and any jump hosts; remove device certificates and deny conditional access.
  • Rotate shared credentials, service accounts, API keys, and database passwords touched by the user.
  • Wipe or lock managed devices via MDM; deprovision EHR mobile apps and revoke push notification keys.
  • Close firewall holes and access rules tied to the user’s IPs or device identifiers.

Implement Access Revocation Protocols

  • Execute a preapproved runbook that defines owners, systems in scope, and escalation points.
  • Time-stamp every action and open an incident ticket to preserve an auditable trail.
  • Notify the privacy officer and security leadership as soon as containment is initiated.

Account Deactivation

After emergency containment, complete formal deprovisioning so access cannot reappear through syncs or role inheritance.

  • Set the user to terminated status in HRIS; ensure downstream deprovisioning propagates to EHR and ancillary apps.
  • Remove role-based privileges, distribution lists, and group memberships that grant clinical or reporting rights.
  • Disable auto-forwarding, shared mailbox access, and scheduled exports tied to the user.
  • Archive the mailbox and workspace content according to retention; preserve evidence for the investigation.

Account Deactivation Documentation

  • Record systems affected, actions taken, approvers, timestamps, and validation screenshots or exports.
  • Capture device serials, certificate IDs, revoked tokens, and credential rotations performed.
  • Store the package with the incident record and restrict access on a need-to-know basis.

Audit Log Review

Conduct a targeted Audit Trail Analysis to determine what the former employee did and whether PHI was exposed.

Scope and Collection

  • Define the review window from last authorized shift through containment completion.
  • Collect EHR access logs, chart access details, export/print events, report runs, and API activity.
  • Pull network, VPN, SSO, endpoint, and DLP logs to correlate sessions, IPs, and devices.

Analysis and Findings

  • Pivot by user ID, IP, and device to reconstruct a session timeline and determine data viewed or exfiltrated.
  • Flag high-risk behaviors: mass record access, bulk exports, unusual hours, or queries outside job function.
  • Quantify patients, data elements, and any files touched; label potential Protected Health Information involved.
  • Preserve immutable copies of logs and generate an investigation summary with evidence references.

Breach Risk Assessment

Evaluate whether the incident meets the threshold for a HIPAA Breach Notification. Use the standard four-factor framework and document your rationale.

  • Nature and extent of PHI: sensitivity, identifiability, and volume of data accessed.
  • Unauthorized person: who accessed the PHI and their likelihood of re-disclosure.
  • Acquisition or viewing: whether PHI was actually viewed, acquired, exported, or copied.
  • Mitigation: speed of containment, revocation of access, and steps taken to reduce risk.

Determine the probability of compromise, make a notification decision, and record approvals. Keep the analysis, evidence, and decision path with the incident file.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Engage counsel early to align actions with federal and state requirements and to preserve privilege over sensitive assessments.

  • Brief legal on timeline, systems, preliminary findings, and mitigation steps taken.
  • Review HIPAA, state breach statutes, contractual obligations, and Business Associate Agreements for notification triggers and deadlines.
  • Coordinate any law enforcement engagement, regulator outreach, and patient communications strategy.
  • Confirm retention holds for logs, devices, and communications related to the incident.

This material is for general guidance; your counsel will tailor requirements to your jurisdiction and contracts.

Communication with Affected Patients

If notification is required, deliver clear, empathetic messages that explain facts and next steps without speculation.

  • Tell patients what happened, what information may have been involved, and when it occurred and was contained.
  • Describe what you are doing to protect them and the organization, and what they can do (e.g., monitor statements, place alerts).
  • Provide contact options (phone and mail), multilingual support as needed, and accessible formats.
  • Coordinate timing and content with legal, compliance, and executive leadership to ensure consistency.

Prevention Measures

Strengthen defenses so former users cannot retain or regain access after separation.

Harden Identity and Access

  • Adopt zero-trust controls: MFA, conditional access, device compliance checks, and session risk policies.
  • Enforce least privilege, individual accounts (no shared logins), and quarterly access recertifications.
  • Automate deprovisioning: trigger removal from all systems at the HRIS termination effective time.

Improve Monitoring and Egress Controls

  • Enable comprehensive EHR audit logging, long enough retention, and near-real-time alerting for risky events.
  • Deploy DLP and egress controls to block bulk exports, unauthorized printing, and unsanctioned cloud sync.
  • Test alerting with tabletop exercises that simulate post-termination access attempts.

Refine Employee Offboarding Procedures

  • Maintain an Access Revocation Protocols checklist covering accounts, devices, tokens, and third-party portals.
  • Require dual-approval for high-risk roles and same-day validation that access is fully revoked.
  • Centralize Account Deactivation Documentation and perform periodic audits for completeness.

By executing swift containment, thorough investigation, and disciplined follow-through, you protect patients, meet obligations, and reduce the chance of repeat incidents.

FAQs

How quickly should EHR access be terminated after employee termination?

Immediately. Ideally, deprovisioning triggers at the termination effective time so the account is disabled before or at the moment notice is delivered. If post-termination access is discovered, treat it as an incident and execute emergency containment without delay.

What steps are involved in audit log review for EHR access?

Define the timeframe; collect EHR audit logs, SSO/VPN records, endpoint events, and DLP data; correlate by user, IP, and device; identify PHI viewed or exported; quantify affected patients and data elements; preserve evidence; and document findings in an Audit Trail Analysis report.

When is a HIPAA breach notification required?

After conducting the four-factor risk assessment, if there is more than a low probability that PHI was compromised, you must proceed with HIPAA Breach Notification and any applicable state notices. Work with counsel to confirm triggers, recipients, content, and timelines.

Organizations may face regulatory investigations, civil monetary penalties, corrective action plans, contractual liability, and reputational harm. The individual may face employment consequences and, in some cases, criminal exposure. Early legal involvement helps manage risk and response accuracy.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles