Before the employee starts

  • Confirm legal name, preferred display name, role, manager, and start date.
  • Identify required email, Microsoft 365 licensing, shared mailboxes, folders, applications, and clinical systems.
  • Create the account early enough to complete MFA and sign-in testing.
  • Prepare the workstation, updates, applications, printer/scanner access, bookmarks, and remote-support tools.

On the first day

  • Verify the employee can sign in to Windows, email, required web portals, and clinical applications.
  • Confirm MFA recovery methods belong to the organization or approved user—not a former employee.
  • Test printing, scanning, shared files, and any role-specific peripherals.
  • Review password-policy criteria—such as required length, complexity, and prohibited characters—along with phishing, remote-access, and patient-information expectations. ClinicsIT never requests or records a user's actual password.

After onboarding

Document what was assigned, retain setup notes, and schedule any delayed access or training. A repeatable checklist prevents the same missing step from becoming a first-day emergency.

Why onboarding needs a repeatable process

Clinic onboarding is more than creating an email address. A new employee may need a Windows identity, multifactor authentication, EHR access, shared folders, printers, scanners, phone extensions, remote-support tools, and access to vendor portals. Missing any one of these can delay patient check-in, billing, or clinical work.

Use a role-based request rather than copying another employee's access without review. A front-desk employee, biller, provider, and office manager usually need different systems and permissions.

A practical preparation timeline

  • Five business days before the start date, confirm the employee's legal name, display name, role, manager, location, start time, and required systems. Create organization-owned accounts and assign only the licenses and groups required for the role.
  • One business day before arrival, verify that the Microsoft or Google account accepts the temporary credentials, confirm required licenses are active, prepare the workstation, test printers and scanners, and stage any MFA enrollment instructions.
  • On the first morning, have the employee complete MFA enrollment, change temporary credentials, sign into Windows and email, and test each required workflow. At the end of the first week, review unresolved access requests and remove temporary privileges.

Example: front-desk onboarding

A front-desk employee may need Windows and email sign-in, the scheduling system, a shared front-desk mailbox, scan-to-folder access, label and document printers, the phone system, and a limited shared-file folder. They normally should not receive global administrator rights, unrestricted billing data, or another employee's credentials.

How to verify the setup

Test the actual workflow, not only the login screen. Have the employee open the shared mailbox, scan a sample document, print to each required printer, reach the correct shared folders, and confirm that restricted folders remain inaccessible.

Record the assigned device, account names, license, groups, MFA status, recovery contact method, and any follow-up work. This creates an auditable baseline for later changes and offboarding.

Need help applying this to your clinic?

ClinicsIT can review the current setup and build a practical, documented process.

Request a consultation