Nurse resignation
PS-1 procedures require EHR, badge, VPN, and email disable on last day with manager checklist completion.
PS-1 requires personnel security policy and procedures addressing purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to implement the Personnel Security family. Healthcare PS-1 connects HR, credentialing, and IAM so hiring, sanction screening, transfers, and terminations protect ePHI throughout the workforce lifecycle.
Establish policy and procedures that ensure personnel who can access ePHI or related facilities are appropriately screened, managed through role changes, and promptly deprovisioned upon separation.
How this control shows up in healthcare and HIPAA-covered environments.
PS-1 procedures require EHR, badge, VPN, and email disable on last day with manager checklist completion.
Policy sets minimum clearance and training gates before temporary clinical access is granted.
Mover process under PS-1 triggers access review so old registration queues are removed when duties change.
Workforce clearance and termination hygiene are HIPAA staples. PS-1 is the policy auditors request before sampling account disable evidence.
How this NIST control supports HIPAA Security Rule expectations.
Include credentialed practitioners and other non-employees with system access in policy scope or equivalent agreements.
Define in policy — best practice is immediate/same day for involuntary terminations and at end of last day for planned separations.
PS-1 is the governing policy; PS-4 is the termination control executed under that policy.
Related controls that commonly accompany PS-1.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.