Overview:
When a staff member leaves your practice or should no longer have access to patient data, their Denticon login must be inactivated promptly. Inactivating a user removes their ability to log in while preserving the full history of all transactions they recorded — which is required for data integrity, auditing, and HIPAA compliance.
Note: Denticon does not allow a user login to be deleted if there are recorded transactions associated with it. Inactivating the user is the correct and only supported method for removing access while preserving the audit trail.
Whenever a user should no longer access the office data through a specific login, the user should be inactivated.
To inactivate a username:
- Navigate to Users
Click Setup in the top menu, then select Security and choose Users from the drop-down. - Select the user
Locate and click on the staff member whose access needs to be removed. - Click Edit
Click the Edit button to open the user record. - Open the Login Info tab
Click the Login Info tab to access the user's login settings. - Reset the password
Change the Password field to a random combination of letters and numbers. This ensures the employee cannot use their existing credentials even if the account were somehow reactivated. - Set Active to "No"
Change the Active field to No. This is what actually removes the user's ability to log in. Rename for alphabetization (optional but recommended)
AddZZin front of the user's last name (e.g., Smith, Jane becomes ZZSmith, Jane). This moves inactive users to the bottom of your user list for easy navigation.⚠️ This is for display/alphabetization only — it has no effect on the active or inactive status of the account.- Save the record
Click the Save button to apply all changes.
After Inactivating a User
Once access has been removed, take the following steps to ensure your practice remains secure:
- Verify the account status shows as inactive by reviewing the user record.
- If the departing employee may have known or used any shared login credentials, review all potentially exposed accounts and update those passwords immediately.
- Confirm no active sessions remain for the inactivated user.
If shared logins exist in your practice, those accounts must be reviewed any time a staff member with knowledge of those credentials departs. Denticon strongly advises against shared logins entirely — see the section below.
HIPAA Requirements: Unique Logins for Every Staff Member
Denticon requires — and Denticon strongly advises — that every staff member is set up with their own unique, name-identifiable login, regardless of whether they are a permanent or temporary employee. This is a HIPAA compliance requirement.
Shared logins create the following problems:
- They do not allow for individual accountability — it cannot be determined which person entered a specific transaction.
- Office administrators cannot identify the source person for any given entry.
- They make it impossible to maintain HIPAA compliance.
- When an employee leaves, shared credentials may remain compromised with no way to know who still has them.
Only unique, name-identifiable staff logins that are genuinely no longer in use should be inactivated. Shared-name logins should not be created in Denticon under any circumstances