Unique user identification, role definitions, provisioning and deprovisioning, emergency access, and the review cadence.
What is in the download
- Format: DOCX
- Length: 6 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the template
The policy implements the access-related standards of the Security Rule — access control at §164.312(a), plus the workforce security and information access management standards of §164.308 — in one document, because in practice they are one workflow. Sections cover: unique user identification (one identity per person, no shared accounts, with a documented exception process for break-glass credentials); a role definition table mapping each role to the systems and classes of ePHI it may access, which is also your minimum-necessary implementation; provisioning — who requests, who approves, who grants, and where the record lives; deprovisioning on termination, with a same-day revocation requirement and a verification step across every system, not just the identity provider; access modification for role changes, the “mover” step that decays first in growing teams; the emergency access procedure §164.312(a)(2)(ii) requires; and the review cadence — a periodic reconciliation of live accounts against the HR roster, with a fill-in frequency and a named owner. Margin citations tie each section to its specification, and the completed example shows the role table filled in for a small telehealth company.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
How to customise it
Start with the role table — it is the heart of the document and the part no template can guess. List your real roles by name, not aspirational ones, and for each role write down what they can access today. Where today’s reality is broader than it should be, you have found remediation work: tighten the access first, then write the policy to match, never the reverse. Set the review cadence to something you will actually sustain — quarterly is the defensible convention, but a documented semi-annual review beats an imaginary quarterly one. Fill in the emergency access procedure with your genuine break-glass mechanism, including where its use gets logged. Finally, name the owner: in a small organisation this is usually the Security Officer wearing another hat, and that is fine, as long as it is written down.
Common mistakes
- Writing the ideal state instead of the real one. A policy promising least-privilege access at a flat-access organisation is evidence of a standard you set and ignored.
- Forgetting the systems outside SSO. The EHR with local accounts, the legacy database, the vendor portal with its own logins — deprovisioning that only covers the identity provider leaves the exact accounts that cause findings.
- No verification step at termination. “IT was told” is not “access was revoked”. The template’s checklist step exists because the gap between the two is the highest-frequency administrative-safeguard failure.
- Reviews that generate no record. An access review that leaves no dated artefact did not happen for evidence purposes. Export the account list, note the discrepancies and fixes, file it.
- Shared accounts surviving as exceptions. Every shared credential breaks audit-log attribution under §164.312(b) as well. Kill them or document a genuinely narrow exception.
Related templates
Access control connects tightly to its neighbours: the password policy governs how the credentials behind each identity are managed, the encryption policy protects the data those identities reach, and the remote work and BYOD policies extend access rules to devices you do not fully control. The annual review checklist includes the access-review reconciliation, and the technical safeguards guide explains the regulatory reasoning behind each section.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.