Workforce authorization: the decision before the access
45 CFR 164.308(a)(3)(ii)(A) requires a procedure for deciding who is authorized to work with ePHI, before that access is granted. Trust is not a procedure, and 'everyone here is trusted' is not an answer to who.
Last verified: 2026-09-08
Ask a clinic who is authorized to work with ePHI, and the honest answer is often “everyone on staff, basically.” That answer describes reality. It does not describe a procedure, and the standard asks for a procedure.
What the rule actually requires
Workforce authorization is an Addressable implementation specification, part of the broader workforce security standard: implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed (45 CFR 164.308(a)(3)(ii)(A)).
Addressable does not mean optional. It means you assess whether the measure is reasonable and appropriate for your clinic, then implement it as written, or implement an equivalent alternative, and document either way. For a clinic where clinical staff routinely handle a child’s session data, records, and billing information, the honest assessment rarely lands on “not reasonable for us.”
Notice the specification covers two paths, not one: authorization or supervision. A workforce member can be independently authorized to work with ePHI, or they can work in a location where ePHI might be accessed while under the supervision of someone who is authorized. The front desk volunteer who never opens the EHR but sits near a screen that displays it falls under this second path, not the first.
Why this is a decision, not a description
The distinction that matters most here is timing. Authorization is a decision made in advance: before a person’s access begins, someone with the standing to make that call determined they should have it, and why. A description written after the fact, an inventory of who currently happens to have access, is not the same thing, even if the two lists look identical on a given day.
This distinction shows up constantly in how clinics actually operate. A new RBT starts, and within a week has a login because someone on the team needed to get them working and shared their own credentials temporarily, “just until IT sets up the real account.” That is not an authorization decision. It is an access grant that happened without one, and the fact that it usually turns out fine does not make it a procedure.
“Everyone here is trusted” is not an answer
This is the sentence that ends most conversations about workforce authorization at small clinics, and it deserves to be taken seriously as a claim, then rejected as a procedure. Trust is not a procedure. It is a feeling about your staff, and it leaves no record. An investigator cannot review a feeling. They can review a decision, who made it, on what basis, and when.
This matters more, not less, in a high-turnover field. ABA clinics hire quickly, often mid-month, often for part-time or field-based roles. “Everyone here is trusted” was true of the team six months ago. It says nothing about the RBT who started three weeks ago and whose actual role, hours, and access needs nobody has separately assessed.
“Trust is not a procedure. It is a feeling about your staff, and it leaves no record.”
What real authorization looks like, next to what most clinics have
| What the rule requires | What most clinics actually have | |
|---|---|---|
| Timing | A decision made before access is granted | Access granted first, formalized later if ever |
| Basis | Tied to role and actual need | “They’re on the team, so they need it” |
| Supervision path | A defined alternative for those not independently authorized | No distinction between authorized and merely present |
| Record | Who decided, on what basis, and when | No record, only the current state of who has access |
The gap here is rarely a bad decision. It is the absence of a decision, access simply accreting as people join, with nobody able to point to the moment anyone actually authorized it.
The short version
- Workforce authorization (164.308(a)(3)(ii)(A)) is Addressable: implement procedures for the authorization and/or supervision of workforce members who work with ePHI or in locations where it might be accessed.
- Addressable does not mean optional. It means you assess whether the measure is reasonable for your clinic, then implement it or document a genuine equivalent.
- Authorization is a decision made in advance, before access is granted, not a description written after the fact of who happens to have access.
- The standard covers supervision as an alternative path: someone who works near ePHI without being independently authorized can instead be supervised by someone who is.
- 'Everyone here is trusted' describes a feeling about your staff. It is not a procedure, and it produces no record an investigator can check.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Administrative safeguards, including workforce security45 CFR 164.308(a)(3)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Access, decided before it's granted.
WiseUpHIPAA ties every access grant to an authorization decision made in advance, tracked to a role, not assumed from who happened to be in the room when someone needed a login.