EMStool LLC — Cadence MIH Scheduling Platform

Workforce Access Offboarding Checklist

Policy #: HIPAA-SEC-010 Effective Date: July 16, 2026 Version: 1.0 Next Review: July 16, 2027

1. Purpose

This document describes the steps to follow whenever a workforce member's access to Cadence needs to be removed or reduced — voluntary separation, termination, role change, or extended leave. It supports the commitment already stated in the Security Officer Designation policy: "Ensure access is revoked immediately upon termination or role change."

This checklist is manual — there is intentionally no automatic HR-system integration triggering it, since no standard HR system exists to integrate with across different Cadence customer organizations. A separate, automated safety net (Section 4) catches any account this checklist misses.

2. When This Applies

3. Checklist

4. Automated Safety Net

A weekly automated check (inactive_user_alert.php) reviews all active (non-disabled) accounts and emails the Administrator(s) any account that hasn't logged in for 90 or more days. This is not a substitute for the checklist above — it exists specifically to catch the case where this checklist was missed or an account was accidentally left enabled after separation.

5. Responsibility

The Security Officer (see Security Officer Designation, HIPAA-SEC-001) is responsible for ensuring this checklist is followed for every separation, and for reviewing the weekly inactive-account alert when it fires.