A policy composed from your clinic's actual facts, a role-by-role access matrix, and a running check on whether every PHI vendor's access attestation is current.
The rule does not ask whether you wrote down an access policy. It asks whether your systems enforce the access decision you already made. Most tools help with the first part and leave the second to memory.
Your access control policy is generated from a maintained clause library against your clinic’s recorded facts. It covers the four-part standard at 164.312(a): unique logins and emergency access as required specifications, session lock and encryption at rest as addressable ones, with your own recorded decisions on the addressable pair rendered directly into the document.
Clauses appear based on what you have recorded about your clinic. Shared workstations, staff using their own devices, a telehealth line, a parent portal, keycode entry at the premises: each pulls in the language that applies, and leaves out the language that does not. Two clinics get two different policies, because they answered different questions.
A policy sitting in a folder is where most compliance programs stop. Here it is one of nine requirements tracked for this control:
Each requirement either holds or it does not, and the board says which.
This is a documentation and readiness system, and the line is worth stating plainly.
The system tracks whether your clinic has recorded the right things: attestations from your vendors, a complete role matrix, finalized addressable decisions, an adopted and current policy. It does not test your logins, probe your vendors’ systems, or measure whether a session locks on any given device. Those remain your responsibility and your vendors’. What the system holds you to is having decided them, written them down, and kept them current.
That distinction matters, because the gap OCR finds is almost never a clinic that made a bad access decision. It is a clinic that never made one, cannot produce the matrix, and has no record of when anyone last looked.
A dated, adopted policy naming your recorded systems. A role-by-role matrix showing what each role may reach. Current attestations from every vendor recorded as touching PHI. A record of your addressable decisions. Not a claim that your access control is technically perfect, evidence that someone made these decisions and can show when.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.