HIPAA Exit Interview & Employee Offboarding
Complete procedures for terminating employees while maintaining HIPAA compliance and PHI security
Why HIPAA Exit Procedures Matter
Departing employees present significant HIPAA risks:
- Continued Access Risk: Forgotten system credentials could be used by successor or misused by departing employee
- Data Exfiltration: Employees may download or copy PHI before leaving
- Breach Potential: Lost/stolen devices or documents containing PHI during transition
- Post-Employment Violations: Former employees may disclose PHI after departure
- Unauthorized Copies: Personal copies of PHI may be retained improperly
- Compliance Documentation: Without proper exit procedures, OCR audits may reveal control gaps
Best Practice: Treat the offboarding process with the same rigor as onboarding to ensure comprehensive compliance.
Pre-Termination Planning
Before Last Day of Work
- Notify IT of termination date and access removal needed
- Notify Privacy Officer of departing employee
- Schedule exit interview (24-48 hours before departure ideal)
- Arrange for return of equipment and credentials
- Document any outstanding compliance issues
- Prepare exit interview documentation package
- Coordinate with department manager on final duties
Department Hand-Off Planning
- Assign successor or transfer duties
- Review active patient assignments (if clinical role)
- Document any pending documentation or records
- Plan transition of on-call or on-coverage responsibilities
- Review any pending investigations or compliance issues
Exit Interview Checklist and Process
Exit Interview Content
- Review confidentiality obligations continuing after employment
- Remind about HIPAA penalties for post-employment violations
- Discuss continued restrictions on PHI use and disclosure
- Verify employee understands confidentiality is indefinite
- Ask if employee has any concerns about compliance or ethics
- Inquire about any knowledge of PHI breaches or violations
- Discuss return of all company property
- Confirm understanding of post-employment restrictions
Exit Interview Questions to Ask
- "Do you have any outstanding patient records or documents that contain PHI at home?"
- "Are you aware of any unauthorized access to patient information during your employment?"
- "Are you familiar with our confidentiality agreement and post-employment obligations?"
- "Do you have any copies of patient information or files on personal devices?"
- "Have you discussed patient cases or information with anyone outside the organization?"
- "Are you aware of any HIPAA violations or security concerns you haven't reported?"
- "Do you understand the consequences of breaching confidentiality after you leave?"
Documentation of Exit Interview
- Date and time of exit interview
- Employee name and last day of employment
- Interviewer name and title
- Topics discussed (confidentiality, return of materials, etc.)
- Employee's responses to key questions
- Any concerns or issues identified
- Employee signature acknowledging completion
- Retained in employee file for 6+ years
Exit Interview Form Template
HIPAA EXIT INTERVIEW FORM
Employee Information:
Name: ______________________________
Department: ______________________________
Position: ______________________________
Last Day of Employment: ______________________________
Exit Interview Conducted By: ______________________________
Title: ______________________________
Date: ______________________________
Confidentiality Obligations Review:
☐ Discussed continuing confidentiality obligations after employment termination
☐ Reviewed HIPAA Privacy Rule restrictions on PHI use/disclosure
☐ Explained that confidentiality obligations are indefinite
☐ Reviewed potential penalties for post-employment violations
☐ Employee confirmed understanding of obligations
Compliance Questions:
Q: Are you aware of any unauthorized access to patient information?
☐ No ☐ Yes (explain below)
Q: Do you have any copies of patient records or PHI at home or on personal devices?
☐ No ☐ Yes (explain below)
Q: Have you discussed patient cases or information with anyone outside the organization?
☐ No ☐ Yes (explain below)
Q: Are you aware of any HIPAA violations or security concerns not previously reported?
☐ No ☐ Yes (explain below)
If Yes to Any Above, Explain:
[Space for explanation]
Property Return Acknowledgment:
☐ Badge/ID card returned
☐ Laptop/desktop computer returned
☐ Phone/mobile device returned
☐ Keys returned
☐ Access cards returned
☐ Any documents containing PHI returned
☐ All outstanding items collected
Items Not Returned (if applicable):
[Description and reason]
System Access Deactivation:
☐ EHR/medical records system access disabled
☐ Email account disabled
☐ Network login disabled
☐ VPN access disabled
☐ Building access revoked
☐ All system access verified as disabled
Employee Acknowledgment:
I acknowledge receipt of this exit interview, understand my continuing confidentiality obligations, and confirm that all return-of-property and compliance matters have been discussed.
Employee Signature: _________________________ Date: _________
Interviewer Signature: _________________________ Date: _________
System Access and Technology Offboarding
IT Offboarding Checklist (Day of Departure)
- Disable EHR/medical records system access at end of shift
- Disable email account access
- Revoke network login and domain access
- Disable VPN access
- Revoke access to shared drives and cloud storage
- Remove from active directory
- Disable badge/building access at entry points
- Revoke parking access (if applicable)
- Disable any mobile device access
- Document date and time of each access removal
- Verify all access is truly disabled (test if possible)
Device Management
- Laptops/Desktops: Collect before last shift, perform data wipe or return to inventory
- Phones/Tablets: Collect company devices, ensure remote wipe is performed
- USB Drives/External Storage: Collect and verify no PHI remains
- Remote Access Tokens: Collect or disable any hardware tokens
- VPN Client: Ensure all VPN access removed
- Badge/Security Card: Collect before employee leaves
Data Security Verification
- Verify no downloads/uploads of PHI in final week
- Check for unusual system access patterns
- Review email forwarding (disable any rules)
- Verify deleted files cannot be recovered
- Ensure employee computer is wiped or destroyed appropriately
- Document all verification activities
Physical Records and Document Management
Record Collection
- Collect any physical files employee may have (patient charts, records)
- Search desk, filing cabinets, and storage areas
- Collect any printed documents with PHI
- Review employee's work area before reassignment
- Identify any reference materials or notes with PHI
- Ensure no take-home files or documents
- Document items collected
Offsite PHI Concerns
- Question employee about any take-home documents or files
- Document any admitted possession of PHI
- Request return of any documents in employee's possession
- If employee refuses to return PHI, escalate to Privacy Officer
- Document non-compliance and take corrective action
Proper Disposal
- Shred all paper documents with PHI appropriately
- Verify documents are destroyed, not just filed
- Use approved destruction vendor if large volume
- Maintain records of destruction
- Photograph destruction if sensitive
Post-Termination Monitoring and Compliance
Ongoing Access Verification
- Monitor for 30 days for any access attempts using former credentials
- Review system logs for unauthorized access
- Verify email account is completely disabled
- Confirm building access is revoked
- Test badge at entry points to ensure deactivation
- Document any access attempts and investigate
Reference and Future Employment
- Provide limited employment verification (dates only, no performance details)
- Do not disclose confidential information about employment
- Do not discuss HIPAA violations with other employers without legal guidance
- Maintain confidentiality of employee records
Breach Risk Monitoring
- Monitor for suspicious activity involving departed employee's credentials
- Alert Privacy Officer if former employee's credentials are used improperly
- Investigate any reports of former employee disclosing PHI
- Document any post-termination violations
- Consider legal action if serious breach occurs
Record Retention and File Management
What to Keep in Employee File
- Exit interview form and documentation
- Confidentiality agreement signed copy
- Background check and screening records
- Training certificates and attendance records
- Any HIPAA violations or discipline records
- Property return receipts
- System access deactivation confirmation
- Final evaluation or performance documentation
Retention Requirements
- Retain all exit documentation for minimum 6 years
- Keep in secure, confidential location
- Restrict access to HR and Privacy Officer
- Do not discuss contents with other employees
- Maintain audit trail of who accesses files
- After retention period, securely destroy records
Frequently Asked Questions
Secure Your Offboarding Process
Medcurity provides exit interview templates, offboarding checklists, and compliance documentation forms.
Get Offboarding Templates