A departing employee does not automatically disappear from the practice’s technology. Every account, forwarding rule, shared credential, external portal, and enrolled device has to be removed deliberately.
Dental staff offboarding should be treated as a same-day access-control process, with the most sensitive systems handled immediately and the employee’s full access footprint audited instead of relying on memory.
The biggest offboarding gap is often not the systems the practice already knows about, but accounts the departing employee created independently.
That can include a personal Gmail account used to forward patient information, a cloud storage account used to share files, or patient communication platform access set up outside the normal practice inventory.
Execute the first offboarding steps in parallel so the departing employee is not locked out of one system while another remains accessible.
Suspend Email Access
Disable email access immediately and check forwarding rules that could continue sending practice mail to a personal account.
Deactivate the PMS Login
Remove access to the practice management system immediately because it contains highly sensitive patient information.
Revoke Active Sessions
End active sessions at termination instead of assuming a password change alone removes every usable connection.
Maintain a clear access inventory so offboarding does not depend on someone remembering every system, portal, credential, and device a staff member used.
PMS, Email, Patient Communication, Insurance
Remove the employee’s Microsoft 365 or Google Workspace account, PMS access, patient communication platform access, insurance portal access, and other known practice-system logins.
Vendor Portals and Cloud Platforms
Remove access to dental supply vendor portals, cloud backup platforms, and any other external services the employee used for practice work.
Rotate Shared Credentials
Rotate shared front-desk PMS logins, shared email accounts, vendor credentials, and Wi-Fi passwords the departing employee knew.
Recover, Wipe, and Remove Forwarding
Recover and wipe practice-owned devices before reuse, remotely remove practice data from enrolled personal devices, and delete any email forwarding rules tied to the employee.
Document the termination of workforce access and preserve a clear record showing when access was revoked, what systems were covered, and who completed the offboarding.
Revoke access across systems in parallel so a departing employee is not locked out of one platform while another remains available.
Trigger the offboarding event once. Every connected access path should close together.
Microsoft 365 or Google Workspace access and active sessions.
OpenDentrix, Eaglesoft, Open Dental, or another PMS account containing patient information.
OpenInsurance portals, vendor systems, patient communication platforms, and other outside services.
OpenShared PMS logins, shared email accounts, vendor credentials, and Wi-Fi passwords the employee knew.
OpenPractice-owned devices and enrolled personal devices that may still contain practice data.
OpenEmail forwarding that could continue delivering practice communications to a personal account.
OpenEkim IT Solutions serves Tampa Bay from our office at 600 N Westshore Blvd, Suite 701. We run a complete offboarding checklist that revokes PHI access the moment employment ends, so nothing lingers past the last day.