EHR DBA vs clinic greeter
Both are on the org chart, but only the DBA can dump databases. PS-2 marks DBA High/Privileged with fingerprint/background and continuous monitoring expectations — greeter stays Low with standard hire screening.
PS-2 requires assigning a risk designation to all organizational positions, establishing screening criteria for individuals filling those positions, and reviewing/updating designations on a defined frequency. In healthcare, a registration clerk, EHR database administrator, and overnight cleaning contractor do not present the same potential for ePHI harm — risk tiers drive how deep screening (PS-3), access (AC-2/AC-6), and monitoring must go.
Classify every workforce and contractor position by the damage that misuse of its duties could cause to ePHI confidentiality, integrity, or availability — then bind screening and access decisions to that tier.
How this control shows up in healthcare and HIPAA-covered environments.
Both are on the org chart, but only the DBA can dump databases. PS-2 marks DBA High/Privileged with fingerprint/background and continuous monitoring expectations — greeter stays Low with standard hire screening.
A revenue-cycle role adds enterprise reporting that can extract full claim files. Annual PS-2 review raises the tier and triggers deeper screening plus tighter AC-6 rights.
Vendor techs enter imaging suites with network access. Position risk designation covers contractor categories so MA-5/PS-3 screening criteria apply before badge and VPN issuance.
Assessors expect a living matrix linking duties to screening depth. Flat screening for every hire while admins hold production EHR rights is a classic gap.
How this NIST control supports HIPAA Security Rule expectations.
No. PS-2 classifies the position risk for personnel decisions; EHR roles implement least privilege technically under AC-2/AC-6.
At least annually and whenever duties, systems, or remote access materially change.
Yes if they can access ePHI systems or sensitive areas — designate volunteer categories and screen accordingly.
Related controls that commonly accompany PS-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.