Involuntary termination at 10:00
HR notifies IT immediately; IdP disable propagates to EHR/VPN; badge kills within the hour; laptop collected — PS-4 SLA met.
PS-4 requires disabling system access within an organization-defined time period upon termination, terminating or revoking authenticators/credentials, retrieving security-related organizational property, and retaining access to related records when needed. It is the personnel control that pairs with AC-2 and PE-2/PE-3 to close the door — logically and physically — when someone leaves.
Complete timely, complete offboarding so former workforce members cannot access ePHI systems, facilities, or retained credentials after termination.
How this control shows up in healthcare and HIPAA-covered environments.
HR notifies IT immediately; IdP disable propagates to EHR/VPN; badge kills within the hour; laptop collected — PS-4 SLA met.
Ship-back kit recovers laptop; accounts disabled on last day; local ePHI sync checked; MDM wipe confirms cleanup.
Quarterly PS-4 audit finds leftover cert; process updated to include certificate inventory on offboarding.
HIPAA termination procedures are frequently sampled by comparing HR exit lists to active accounts. Timing gaps are classic findings.
How this NIST control supports HIPAA Security Rule expectations.
Define SLAs by risk — involuntary and privileged exits often need hours, not days. Document and meet them.
AC-2 is the account management control; PS-4 is the personnel process that triggers disable/retrieve actions upon termination.
Retain organizational records appropriately, but do not leave the person's interactive credentials active. Use litigation-hold / shared mailbox patterns instead.
Related controls that commonly accompany PS-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.