PS-4 Personnel Security

Personnel Termination

High Risk Moderate Low Cost

PS-4 requires disabling system access within an organization-defined time period upon termination, terminating or revoking authenticators/credentials, retrieving security-related organizational property, and retaining access to related records when needed. It is the personnel control that pairs with AC-2 and PE-2/PE-3 to close the door — logically and physically — when someone leaves.

Control Objective

Complete timely, complete offboarding so former workforce members cannot access ePHI systems, facilities, or retained credentials after termination.

Implementation Guidance

  1. Define SLAs: e.g., disable IdP/EHR within hours of involuntary termination; same day for voluntary where risk is elevated.
  2. Use a termination checklist: accounts, MFA, VPN, email, badges, keys, laptop, tokens, VPN certs, vendor portals.
  3. Coordinate HR → IT/security notifications automatically when possible.
  4. Retrieve property and document exceptions (remote ship-back).
  5. Preserve records needed for investigations; do not destroy audit history.
  6. Notify relevant managers and update access lists (PE-2).
  7. For high-risk exits, monitor for anomalous access attempts post-termination.
  8. Include contractors and students — not only W-2 employees.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Involuntary termination at 10:00

HR notifies IT immediately; IdP disable propagates to EHR/VPN; badge kills within the hour; laptop collected — PS-4 SLA met.

Remote coder resigns

Ship-back kit recovers laptop; accounts disabled on last day; local ePHI sync checked; MDM wipe confirms cleanup.

Contractor ends but VPN cert remains

Quarterly PS-4 audit finds leftover cert; process updated to include certificate inventory on offboarding.

Best Practices

  • Same-day disable for high-risk exits.
  • Comprehensive checklist including physical access.
  • Automated HR triggers.
  • Post-termination access attempt monitoring.
  • Cover non-employees.
  • Measure time-to-revoke as a KPI.

Common Gaps & Violations

  • EHR access lingering days after last day.
  • Badge not collected/disabled.
  • Personal email forwarding left on.
  • Shared passwords known to the departed user unchanged.
  • Contractors omitted from offboarding.

Required Documentation

  • Personnel termination / offboarding procedure
  • Termination checklist template
  • SLA definitions
  • Sample completed offboarding tickets
  • Metrics on time-to-revoke

How to Test & Validate

  1. Sample recent terminations for timely account disable evidence.
  2. Verify badge/key recovery or disable records.
  3. Confirm property recovery or ship-back tickets.
  4. Check contractor offboarding samples.
  5. Review post-termination auth failures/alerts.

Audit Considerations

HIPAA termination procedures are frequently sampled by comparing HR exit lists to active accounts. Timing gaps are classic findings.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(C) Termination Procedures — implement procedures for terminating access to ePHI when employment ends.
  • 164.312(a)(1) Access Control — former users must not retain authorized access.
  • 164.310(a) Facility Access — physical access removal accompanies logical termination.
  • 164.308(a)(3)(ii)(A) Authorization and/or Supervision — workforce access lifecycle includes exit.

Compliance Tips

  • One checklist owned jointly by HR and IT with timestamps.
  • Disable IdP first so downstream SSO apps fall closed.
  • Include 'shared secret reset' when the person knew departmental passwords.

Frequently Asked Questions

How fast is fast enough?

Define SLAs by risk — involuntary and privileged exits often need hours, not days. Document and meet them.

How does PS-4 relate to AC-2?

AC-2 is the account management control; PS-4 is the personnel process that triggers disable/retrieve actions upon termination.

What about retaining email for business continuity?

Retain organizational records appropriately, but do not leave the person's interactive credentials active. Use litigation-hold / shared mailbox patterns instead.

References & Resources

  • NIST SP 800-53 Rev. 5 — PS-4
  • HIPAA § 164.308(a)(3)
  • Related controls: AC-2, PE-2, PE-3, PS-5, IA-4

Need Help Implementing PS-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.