Workforce clearance: appropriate access, not a background check requirement
45 CFR 164.308(a)(3)(ii)(B) requires a procedure to determine that a workforce member's access to ePHI is appropriate. It does not require a background check on everyone, it requires you to have actually asked the question.
Last verified: 2026-09-08
Workforce clearance is the standard most likely to be misread, in both directions. Some clinics assume it means formal background checks for every hire and quietly ignore it because that feels disproportionate for an RBT role. Others assume “clearance” is just a formal word for “we hired them” and never separately consider it. Both readings miss what the standard actually asks for.
What the rule actually requires
Workforce clearance procedure is an Addressable implementation specification: implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate (45 CFR 164.308(a)(3)(ii)(B)).
The rule’s own drafting history is worth knowing here, because it heads off the most common misreading. Commenters asked HHS to drop the word “clearance” in favor of “authorization,” worried it implied mandatory background checks. HHS kept “clearance” specifically because it better captured a screening process, but clarified the actual text to read as it does now: a procedure to determine appropriateness, not a specific screening method. The standard is explicit that this can range from minimal procedures to more stringent ones, calibrated to the role, the risk, and what your own risk analysis actually shows.
What “appropriate” is actually asking
The question this standard poses is narrower and more practical than “is this person trustworthy.” It is: given what this specific role needs to do, is the access being granted actually matched to that need. A front-desk role that schedules appointments needs different access than a BCBA writing clinical assessments, and a clearance procedure is what makes that distinction on purpose, rather than by accident.
“This is a mandate to have a procedure, not a mandate to run a background check on everyone.”
How clearance differs from authorization
Clearance (164.308(a)(3)(ii)(B)) and authorization (164.308(a)(3)(ii)(A)) sit next to each other and get conflated constantly, but they answer different questions. Authorization decides that a category of access should exist for a role. Clearance is the process that determines whether a specific person is appropriate to hold that access, given what the role actually requires. A clinic can have a clear authorization structure, defined roles with defined access levels, and still fail clearance if nobody ever checks that a given hire’s access matches what their actual role needs before it’s granted.
What a real procedure looks like, next to what most clinics have
| What the rule requires | What most clinics actually have | |
|---|---|---|
| Basis for access | Matched to role, scaled to risk, actually assessed | Granted by job title, uniformly, without a distinct check |
| Method | Yours to calibrate, minimal to stringent, and defensible | Either nothing, or an assumption that “hired” equals “cleared” |
| Documentation | A record that the appropriateness question was asked and answered | No record either way |
| Common misreading | Correctly scoped: a procedure, not a mandatory background check | Ignored because background checks feel disproportionate for the role |
The most common failure here is not a wrong decision about who gets access. It is that appropriateness was never actually a question anyone asked, access simply followed from the job title, with no procedure standing between the two.
The short version
- Workforce clearance (164.308(a)(3)(ii)(B)) is Addressable: implement procedures to determine that a workforce member's access to ePHI is appropriate.
- This is not a mandate to run background checks on every hire. It is a mandate to have an actual procedure for deciding what 'appropriate' means, and to apply it.
- The standard allows a range, from minimal to more stringent screening, based on your own risk analysis. What's reasonable for a front-desk role differs from what's reasonable for someone with full clinical record access.
- Clearance and authorization (164.308(a)(3)(ii)(A)) are related but distinct. Authorization decides that access should exist. Clearance is the process that determines the person is appropriate to hold it.
- The failure pattern is not usually a bad clearance decision. It is no clearance process at all, access assigned by role title with nobody having asked the appropriateness question.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Administrative safeguards, including workforce security45 CFR 164.308(a)(3)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Access appropriate to the role, checked before it's granted.
WiseUpHIPAA ties each access grant to a documented appropriateness decision, scaled to the role, not skipped because the hire felt routine.