Policy #: HIPAA-SEC-010Effective Date: July 16, 2026Version: 1.0Next Review: July 16, 2027
1. Purpose
This document describes the steps to follow whenever a workforce member's access to Cadence needs to be removed or reduced — voluntary separation, termination, role change, or extended leave. It supports the commitment already stated in the Security Officer Designation policy: "Ensure access is revoked immediately upon termination or role change."
This checklist is manual — there is intentionally no automatic HR-system integration triggering it, since no standard HR system exists to integrate with across different Cadence customer organizations. A separate, automated safety net (Section 4) catches any account this checklist misses.
2. When This Applies
Voluntary resignation or planned separation
Involuntary termination (for cause or otherwise)
Role change where the workforce member no longer needs the same level of access
Extended leave of absence where access should be suspended, not just left active
3. Checklist
4. Automated Safety Net
A weekly automated check (inactive_user_alert.php) reviews all active (non-disabled) accounts and emails the Administrator(s) any account that hasn't logged in for 90 or more days. This is not a substitute for the checklist above — it exists specifically to catch the case where this checklist was missed or an account was accidentally left enabled after separation.
5. Responsibility
The Security Officer (see Security Officer Designation, HIPAA-SEC-001) is responsible for ensuring this checklist is followed for every separation, and for reviewing the weekly inactive-account alert when it fires.