Access control

Access control, tracked against your real roles and vendors

A policy composed from your clinic's actual facts, a role-by-role access matrix, and a running check on whether every PHI vendor's access attestation is current.

The rule does not ask whether you wrote down an access policy. It asks whether your systems enforce the access decision you already made. Most tools help with the first part and leave the second to memory.

The policy is composed, not downloaded

Your access control policy is generated from a maintained clause library against your clinic’s recorded facts. It covers the four-part standard at 164.312(a): unique logins and emergency access as required specifications, session lock and encryption at rest as addressable ones, with your own recorded decisions on the addressable pair rendered directly into the document.

Clauses appear based on what you have recorded about your clinic. Shared workstations, staff using their own devices, a telehealth line, a parent portal, keycode entry at the premises: each pulls in the language that applies, and leaves out the language that does not. Two clinics get two different policies, because they answered different questions.

What gets tracked after the policy exists

A policy sitting in a folder is where most compliance programs stop. Here it is one of nine requirements tracked for this control:

  • The policy is active, and has been reviewed within the last twelve months.
  • Every vendor recorded as touching PHI has a current access control attestation on file.
  • Your role access matrix covers every active role in your workforce, so there is a documented answer for what each role may reach.
  • Your emergency access procedure is named, not implied.
  • Your decisions on the two addressable specifications are finalized and recorded, not left open.
  • The policy has been formally adopted, and its underlying facts have not drifted since it was written.

Each requirement either holds or it does not, and the board says which.

What this is, and what it is not

This is a documentation and readiness system, and the line is worth stating plainly.

The system tracks whether your clinic has recorded the right things: attestations from your vendors, a complete role matrix, finalized addressable decisions, an adopted and current policy. It does not test your logins, probe your vendors’ systems, or measure whether a session locks on any given device. Those remain your responsibility and your vendors’. What the system holds you to is having decided them, written them down, and kept them current.

That distinction matters, because the gap OCR finds is almost never a clinic that made a bad access decision. It is a clinic that never made one, cannot produce the matrix, and has no record of when anyone last looked.

What an investigator gets

A dated, adopted policy naming your recorded systems. A role-by-role matrix showing what each role may reach. Current attestations from every vendor recorded as touching PHI. A record of your addressable decisions. Not a claim that your access control is technically perfect, evidence that someone made these decisions and can show when.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.