164.312(a)(1) Technical Safeguards

Access Control

Critical Risk Complex High

Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software programs that have been granted access rights.

Implementation Guidance

Implement technical policies and procedures so that only persons or software programs granted rights under 164.308(a)(4) can reach ePHI. Access control is the standard; four implementation specifications sit beneath it.

Required specifications:
• Unique user identification — 164.312(a)(2)(i). Assign every user a distinct name or number and never permit shared or generic logins. Without unique identity, audit logs cannot attribute activity to a person, and both accountability and the sanction process collapse.
• Emergency access procedure — 164.312(a)(2)(ii). Establish a documented route to ePHI when normal authentication is unavailable: a break-glass account, a sealed credential envelope, or a documented escalation to a named administrator. It must be tested, logged and reviewed after every use.

Addressable specifications:
• Automatic logoff — 164.312(a)(2)(iii). Terminate sessions after a defined period of inactivity. Set the interval from the risk of the location: short in shared clinical areas, longer where a workstation is physically controlled.
• Encryption and decryption — 164.312(a)(2)(iv). Encrypt ePHI at rest where reasonable and appropriate. Where you decide not to, record the reasoning and the alternative safeguard. Encryption is also the only route to the breach-notification safe harbour at 164.402.

Implementation approach:
- Build the access model from job function, not from individual request, so entitlements are reviewable
- Apply least privilege and separation of duties; restrict and separately log administrative rights
- Provision through a single authoritative process tied to HR joiners, movers and leavers
- Review entitlements at least quarterly, and immediately on role change or termination
- Extend the same model to databases, backups, reporting tools and cloud consoles, not just the clinical application

Required Documentation

• Access control policy and supporting procedures
• Role definitions with the ePHI entitlements attached to each
• Unique user identification standard, and any approved exception with justification
• Emergency access (break-glass) procedure, test records and post-use review log
• Automatic logoff configuration, with the inactivity interval per location and the risk basis for it
• Encryption-at-rest decision record, or documented equivalent alternative under 164.306(d)
• Access request, approval, modification and revocation records
• Periodic entitlement review evidence, including reviewer, date and actions taken
• Termination checklists showing access removal, with timestamps
• Privileged account inventory and approval records

Best Practices

• Enforce role-based access built from job function, and review the role catalogue annually
• Deploy multi-factor authentication for remote access, administrative accounts and any internet-facing system
• Remove standing administrative privilege in favour of just-in-time elevation with automatic expiry
• Keep the leaver process automated from the HR record so revocation cannot depend on someone remembering
• Encrypt ePHI at rest everywhere it is reasonable, and record the decision where it is not
• Alert on privileged account creation, group membership change and failed authorisation spikes
• Test the emergency access procedure at least annually, and treat every real use as a reviewable event
• Include cloud consoles, database admin tools and integration accounts in the same access model
• Attest entitlements with the business owner who understands the job, not only with IT

Common Violations

• Shared or generic logins that make audit trails unattributable
• Terminated employees retaining active accounts, sometimes for months
• Access accumulating across role changes so long-tenured staff hold far more than their job requires
• No emergency access procedure, or one that has never been tested
• Automatic logoff disabled for convenience with no documented risk decision
• Treating the addressable encryption specification as optional and recording no decision at all
• Entitlement reviews that are signed off without anyone actually examining the entitlements
• Access controls applied to the main application but not to backups, test copies or reporting databases
• Unmanaged service and integration accounts holding broad standing access to ePHI

Testing Procedures

• Reconcile the full user list against current HR records and confirm every account maps to one identified individual
• Search for shared, generic, default and service accounts, and confirm each is either removed or justified and controlled
• Sample recent leavers and confirm access was revoked, checking the actual timestamp against policy
• Sample recent role changes and confirm entitlements were reduced, not just added to
• Attempt access to ePHI with an account that should not hold it, and confirm denial is enforced and logged
• Execute the emergency access procedure in a controlled test and confirm it works, is logged and triggers review
• Verify automatic logoff by leaving a session idle past the configured interval on each workstation class
• Confirm encryption at rest on servers, laptops, mobile devices, removable media and backups
• Review privileged accounts and confirm administrative rights are separately approved and monitored
• Confirm access controls apply to backup copies, test environments and reporting databases holding real ePHI

Implementation Resources

Download expert-developed templates and checklists to implement this control:

Quick Facts

Control ID 164.312(a)(1)
Category Technical Safeguards
Risk Level Critical
Difficulty Complex
Est. Cost High
Timeframe 3-6 months
Last Updated Sep 3, 2026

Need Help Implementing This Control?

Our certified HIPAA experts can help you implement this control correctly and efficiently.