Staff turnover is one of the most consistently underestimated IT security risks in dental practices throughout the region. Tampa Bay’s dental job market is competitive. Dental assistants, hygienists, and front desk staff move between practices with some regularity, and the IT consequence of that movement, departed staff retaining active access to practice management software, imaging systems, email accounts, and cloud platforms, creates a HIPAA exposure that most practices discover only when something goes wrong.
Ekim IT Solutions is the dental-exclusive IT provider serving Tampa Bay from our office at 600 N Westshore Blvd, Suite 701, Tampa, FL 33609.
A former employee who can still log into Dentrix, access patient scheduling, or retrieve patient contact information from a cloud communication platform represents an active breach risk regardless of whether they intend to misuse that access.
Most dental practice data breaches involving former employees occur not because the departed staff member intended harm, but because their credentials were never deactivated and remained valid entry points that were later exploited.
Check off each step completed for this staff departure.
PMS user account deactivated immediately, removing login ability from any workstation including home access
Email disabled and Microsoft 365 or Google Workspace credentials revoked, with mail forwarded to a designated inbox for a defined period
Third-party platform access removed, including patient communication tools like Weave, NexHealth, or Solutionreach and any other cloud platform
The reverse process, provisioning IT access for a new dental staff member, has its own risk if done inconsistently. A new front desk hire who is given the office manager’s login credentials because creating a new account seems inconvenient has access to every function the office manager’s account controls. Ekim IT Solutions creates new user accounts with appropriate role-based permissions for every new Tampa Bay dental staff member, establishing the correct access level from day one rather than inheriting permissions from a previous employee or sharing credentials.
HIPAA requires that covered entities implement access controls that restrict PHI access to authorized users, and that those access controls be documented and updated when staff roles change. Staff turnover is a material change to the access control environment that must be reflected in updated HIPAA documentation. Ekim IT Solutions updates access control documentation in the HIPAA Security Risk Assessment for Tampa Bay practices whenever staff access is added or removed.
Ekim IT Solutions serves Tampa Bay from our office at 600 N Westshore Blvd, Suite 701. We build the offboarding process that closes access the moment someone leaves, before it becomes a breach risk you discover too late.