If your HR source is scoped to not aggregate accounts after a certain amount of time, it will delete the Identity. So it is possible for prior login IDs to be used if the IDN Identity is removed.
There is a parameter that can be set on the source that will not delete the Identity.