PS-2 Personnel Security

Position Risk Designation

High Risk Moderate Low Cost

PS-2 requires assigning a risk designation to all organizational positions, establishing screening criteria for individuals filling those positions, and reviewing/updating designations on a defined frequency. In healthcare, a registration clerk, EHR database administrator, and overnight cleaning contractor do not present the same potential for ePHI harm — risk tiers drive how deep screening (PS-3), access (AC-2/AC-6), and monitoring must go.

Control Objective

Classify every workforce and contractor position by the damage that misuse of its duties could cause to ePHI confidentiality, integrity, or availability — then bind screening and access decisions to that tier.

Implementation Guidance

  1. Inventory positions that create, view, alter, export, or administer systems holding ePHI — include students, temps, and BA staff on-site.
  2. Define risk tiers (e.g., Low / Moderate / High / Privileged) using criteria such as volume of ePHI access, break-glass rights, admin privileges, and physical facility reach.
  3. Map each job code/title to a tier in HRIS with an owner (privacy/security/HR).
  4. Publish screening criteria per tier (background check depth, sanction checks, credential verification).
  5. Require tier confirmation before provisioning EHR or privileged accounts.
  6. Review designations at least annually and when job duties, EHR modules, or remote access models change.
  7. Escalate positions that gain VIP chart access, research data pulls, or infrastructure admin rights.
  8. Document exceptions (emergency hires) with time-boxed interim access and catch-up screening.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR DBA vs clinic greeter

Both are on the org chart, but only the DBA can dump databases. PS-2 marks DBA High/Privileged with fingerprint/background and continuous monitoring expectations — greeter stays Low with standard hire screening.

Coding team gains bulk export

A revenue-cycle role adds enterprise reporting that can extract full claim files. Annual PS-2 review raises the tier and triggers deeper screening plus tighter AC-6 rights.

Traveling biomedical contractor

Vendor techs enter imaging suites with network access. Position risk designation covers contractor categories so MA-5/PS-3 screening criteria apply before badge and VPN issuance.

Best Practices

  • Tie risk tiers to HR job codes, not informal titles.
  • Reassess when EHR privileges expand.
  • Include non-employees who touch ePHI environments.
  • Publish a simple matrix auditors can read.
  • Link PS-2 tiers to PS-3 screening packages.
  • Flag privileged IT and privacy officer roles explicitly.

Common Gaps & Violations

  • One screening package for all hires regardless of ePHI reach.
  • Job risk never updated after role redesign.
  • Contractors omitted from position designation.
  • Privileged IT roles treated like standard office staff.
  • No documented review frequency.

Required Documentation

  • Position risk designation policy
  • Job-code-to-risk-tier matrix
  • Screening criteria by tier
  • Annual review records
  • Exception / interim-access logs

How to Test & Validate

  1. Sample high-ePHI roles and confirm tier assignment exists.
  2. Verify privileged IT/privacy roles are High or Privileged.
  3. Check last designation review date.
  4. Trace one new hire: tier set before EHR access granted.
  5. Confirm contractor categories appear in the matrix.

Audit Considerations

Assessors expect a living matrix linking duties to screening depth. Flat screening for every hire while admins hold production EHR rights is a classic gap.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — ensure workforce members have appropriate access and that clearance processes match duties.
  • 164.308(a)(3)(ii)(B) Workforce Clearance Procedures — determine that access of a workforce member to ePHI is appropriate.
  • 164.308(a)(4) Information Access Management — access authorization should reflect role risk.
  • 164.308(a)(1) Risk Analysis — position risk informs overall risk posture for insider threats.

Compliance Tips

  • Put PS-2 tier on the access request form as a required field.
  • Sync HR job-change events to re-evaluate designation (pairs with PS-5).
  • Keep the tier list short enough that managers actually use it.

Frequently Asked Questions

Is PS-2 the same as an access role in the EHR?

No. PS-2 classifies the position risk for personnel decisions; EHR roles implement least privilege technically under AC-2/AC-6.

How often should designations be reviewed?

At least annually and whenever duties, systems, or remote access materially change.

Do volunteers need risk designations?

Yes if they can access ePHI systems or sensitive areas — designate volunteer categories and screen accordingly.

References & Resources

  • NIST SP 800-53 Rev. 5 — PS-2
  • HIPAA § 164.308(a)(3)
  • Related controls: PS-3, AC-5, AC-6, PL-2, PE-2

Need Help Implementing PS-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.