Definition
Access controls are technical and administrative measures that allow authorized people or software to access ePHI while preventing unauthorized access.
In practice
- A support engineer receives time-limited access approved for a specific incident.
- A terminated workforce member's access is revoked across SSO, applications, VPN, and cloud consoles.
Who this applies to
- System owners and identity teams
- Workforce members with ePHI access
- Vendors with administrative or support access
What the rule asks for
- Assign unique user identification where appropriate.
- Establish emergency access procedures, automatic logoff decisions, and encryption or decryption mechanisms as appropriate.
- Review access based on role, change, termination, and risk.
How teams put it into practice
- Use joiner-mover-leaver workflows with evidence and ownership.
- Separate everyday identities from privileged administration.
- Review service accounts, support access, and break-glass events.
Common mistakes
- Sharing accounts for convenience.
- Granting standing administrator access to vendors.
- Removing a user from the directory but leaving application, API, or backup access active.
Questions that come up
Does HIPAA require MFA?
HIPAA does not prescribe one universal authentication technology; organizations should evaluate authentication risks and implement reasonable and appropriate measures.
References
- Access control guidance HHS Office for Civil Rights