HR Cybersecurity: Employee Records, Offboarding, and PII

This post contains affiliate links. If you purchase through our links we may earn a small commission at no extra cost to you.

HR handles more sensitive data than almost any other department in a small business — Social Security numbers, banking information, medical records, background checks, salary data, performance reviews, disciplinary records. And HR is often the department LEAST invested in cybersecurity because “we’re just handling paperwork.” That mismatch creates one of the most common and most damaging small business data breaches: HR data exposure through misplaced files, departing employees walking out with sensitive information, or attackers targeting HR mailboxes specifically because they know what’s there. This guide covers HR-specific cybersecurity: what data to protect, how to secure employee records, offboarding procedures that don’t leak, and the compliance intersections most small businesses miss.

The HR data classification map

Highest sensitivity — regulated data

  • Social Security Numbers (SSNs)
  • Bank account and routing numbers (for direct deposit)
  • Medical records / health information (HIPAA-adjacent even if not full HIPAA)
  • Immigration documents (I-9 supporting records)
  • Background check reports
  • Wage and tax data (W-2, 1099 records)

High sensitivity — protected but less regulated

  • Salary and compensation data
  • Performance reviews
  • Disciplinary actions
  • Termination reasons
  • Retirement account information (TSP, 401k)

Medium sensitivity — internal only

  • Employee contact information
  • Emergency contacts
  • Job descriptions
  • Organizational charts
  • Training records

Public/low sensitivity

  • Company directory (business contact info)
  • Job titles
  • Team assignments (when appropriate to share)

See our data classification policy guide for the broader classification framework.

Where HR data actually lives (and where it leaks)

HRIS / payroll systems

Gusto, Rippling, ADP, Paychex — the primary storage location for most HR data. Generally well-secured by vendors but requires:

  • Strong access controls (who in HR can see what)
  • MFA enforced for admin accounts
  • Audit logging enabled
  • Access reviewed quarterly

Email attachments

  • Job applications with resumes in inbox
  • W-2 forms sent via email during tax season
  • Direct deposit forms with bank info
  • Background check results emailed
  • SSN and I-9 documents forwarded internally

Email is the #1 HR data leak vector. Establish policy: sensitive documents go to secure portal, not email attachment.

Shared drives / cloud storage

  • HR folder on SharePoint/Google Drive/OneDrive
  • Often over-permissioned (“HR can access everything”)
  • Terminated employees may retain access to personal files
  • Regular access audit essential

Physical documents

  • Employee files in filing cabinets
  • Signed forms awaiting scanning
  • Printed copies of sensitive documents
  • Termination paperwork requiring signatures

Endpoint devices

  • HR staff laptops (often traveling to conferences, home offices)
  • USB drives with employee data
  • Old computers with cached files

HR-specific security controls

Access control for HR data

  • Principle of least privilege — not everyone in HR needs access to everything
  • Separate roles: recruiting, benefits, compensation, employee relations
  • SSN visibility restricted to payroll/tax function only
  • Medical data (ADA accommodations) separate from general HR file

Encryption at rest and in transit

  • HRIS/payroll systems: verify encryption in vendor’s SOC 2 report
  • Endpoint drives: full disk encryption enabled (BitLocker Windows, FileVault Mac)
  • Email: encrypt sensitive attachments or use secure portal
  • Cloud storage: verify encryption on shared drives holding HR data

Secure file sharing

  • Don’t email W-2, SSN, banking info
  • Use secure portal (SharePoint with limited access, Box, or HRIS document upload)
  • Set expiration dates on shared links
  • Track who accessed what and when

Physical security

  • Locked filing cabinets for physical employee records
  • Shredding old employee documents (not just recycling)
  • Access-controlled HR office space if possible
  • Clean desk policy — no sensitive papers left visible

The offboarding process — the biggest HR security event

Terminations are when employee data risk peaks. Whether voluntary or involuntary, offboarding must include:

Immediate (day of termination)

  • Disable SSO / M365 account (single click via IT)
  • Revoke access to shared drives and specific sensitive folders
  • Disable VPN access
  • Change any shared credentials the employee had access to (bank, admin passwords, etc.)
  • Retrieve company hardware (laptop, phone, badges)

Within 24 hours

  • Forward email to manager or shared mailbox
  • Preserve email for legal/business record purposes (per retention policy)
  • Retrieve any external accounts (SaaS logins, contractor sites)
  • Review recent email/file activity for suspicious downloads
  • Update password manager to revoke access

Within 1 week

  • Formal exit interview (with HR)
  • Written acknowledgment of company property returned and data policies
  • Update authentication logs (former employee removed from all systems)
  • Verify no data exfiltration in recent access logs

Within 30 days

  • Archive employee records per retention policy
  • Final payroll processed
  • Benefits/insurance status updated
  • Any severance or termination documents secured

The offboarding checklist as a written procedure

Document every step. Assign owners (IT, HR, direct manager). Track completion. Missing a single step (like forgetting to disable a shared cloud service) creates ongoing exposure.

Departing employee data exfiltration — the specific risk

Data theft during resignation/termination is more common than most small businesses realize:

  • Sales reps take client lists
  • Engineers take code or design files
  • Marketing takes content or campaign data
  • Executive assistants take proprietary process documentation

Defenses:

  • DLP (Data Loss Prevention) monitoring on email + file transfers
  • Access log monitoring for unusual download patterns
  • USB port control (block or monitor)
  • Clear IP ownership language in employment contracts
  • Written notification of data return obligation at offboarding

Onboarding — building security habits from day one

New hire security day 1

  • Acceptable Use Policy review and signed acknowledgment
  • Password manager account provisioned
  • MFA enabled on all business accounts
  • Security awareness training scheduled (within week 1)
  • Company hardware assigned with proper security config

First month

  • Complete security awareness training (KnowBe4, Proofpoint, or similar)
  • Simulated phishing test
  • Review data handling responsibilities for their role
  • Establish role-appropriate access (least privilege)

See our best security awareness training platforms.

Compliance intersections HR should know

FTC Safeguards Rule (financial institutions)

  • Applies broader than most think — accountants, auto dealers, mortgage brokers, financial advisors
  • Requires WISP (Written Information Security Program)
  • Employee training and access controls specifically required
  • See our FTC Safeguards Rule guide

State privacy laws (CCPA, CPRA, others)

  • Employee data increasingly covered by state privacy laws
  • California CPRA covers HR data
  • Growing state-level coverage

HIPAA (self-insured health plans)

  • Self-insured health plans trigger HIPAA obligations for the employer
  • Sponsored health plan data must be firewalled from broader HR data
  • See our HIPAA compliance guide

Background check regulations

  • Fair Credit Reporting Act (FCRA) governs background check handling
  • Ban-the-box laws (state-specific) affect when background checks occur
  • Retention requirements for adverse action documentation

State data breach notification laws

  • SSN, driver’s license, financial account = triggering data types
  • Timeline requirements vary by state (30-90 days typical)
  • See our data privacy laws guide

Common HR cybersecurity mistakes

  • Emailing SSN or bank info. Even to the employee — use secure portal.
  • Storing tax forms in email. Purge W-2/W-4/1099 attachments from inbox after processing.
  • No offboarding checklist. Steps get missed; former employees retain access.
  • Shared “HR@” mailbox monitored by anyone with HR title. Access must be limited by role/need.
  • Old employee files in unsecured shared drives. Encryption + access control + retention policy needed.
  • No document retention/destruction policy. Keep everything forever = growing liability surface.
  • Physical documents unsecured. Filing cabinet in shared area = anyone can browse.
  • HR laptops without full disk encryption. Lost laptop = data breach.

The HR security policy — a template starting point

Every small business HR function should have written policy covering:

  1. Data classification (what’s sensitive, what’s not)
  2. Access controls (who accesses what)
  3. Storage locations (approved systems only)
  4. Email/sharing restrictions (no sensitive data via email)
  5. Onboarding procedure (what security setup happens for new hires)
  6. Offboarding procedure (what security cleanup happens for departures)
  7. Retention schedule (how long records are kept, when destroyed)
  8. Incident response (what to do when data exposure occurs)
  9. Training requirements (all HR staff certified annually)
  10. Vendor requirements (HRIS/payroll SOC 2 review)

Recommended tools

Related SBSG topics

Foundational: data classification policy, small business cybersecurity policy, data retention and destruction. Access management: least privilege, privileged access management. Training: security awareness training platforms, employee cybersecurity training. Compliance: data privacy laws, HIPAA compliance, FTC Safeguards Rule. Departure risk: insider threat prevention. Cross-cluster (SBITG): NTFS and SharePoint permissions for the IT-ops side of HR data storage.

Key takeaways

  • HR handles more regulated data (SSN, bank, medical) than most departments; treat security accordingly.
  • Email is the #1 HR data leak vector — use secure portals for sensitive documents, never email attachments.
  • Offboarding is the highest-risk HR security event — written checklist required, IT + HR + manager all with clear owners.
  • Onboarding sets security habits — Day 1 password manager + MFA + AUP acknowledgment; Week 1 security training.
  • Compliance intersections (FTC Safeguards, HIPAA, state privacy laws, FCRA) directly regulate HR data — know which apply to your business.

FAQ

How long should we keep employee records after termination? Depends on record type and state. General guidelines: I-9 forms (3 years after hire or 1 year after termination, whichever later), payroll (4 years for tax purposes), personnel files (7 years typical), medical records separate for 30+ years. Establish written retention schedule; document destruction with certificate of destruction for sensitive materials.

Should our HRIS have MFA? Absolutely yes — HRIS admin accounts should have MFA enforced, ideally hardware key. HRIS holds SSN, bank info, salary data — top-value target. Every major HRIS (Gusto, Rippling, ADP, Paychex, BambooHR, Workday) supports MFA; enable it universally.

Can I use consumer file sharing (Dropbox, Google Drive personal) for HR data? No. Consumer tiers of these services lack the audit logging, access controls, and vendor accountability appropriate for regulated HR data. Business tier of same vendors is fine (Dropbox Business, Google Workspace, OneDrive for Business). Verify SOC 2 report on vendor before signing.

Recommended companion
Data Privacy Pack (HR + Records Policies)
HR handles the most regulated data in your business — SSN, banking, medical, background checks. The Data Privacy Pack includes the written data classification, retention, and destruction policies that make your HR cybersecurity practices audit-ready and compliance-defensible.

Get the Data Privacy Pack →

Similar Posts