Traveler nurse onboarding
Agency nurse needs EHR access same week. PS-3 checklist confirms identity, license, and exclusion screening completed (or agency attestation accepted under BAA) before credentials issue.
PS-3 requires screening individuals prior to authorizing access to the system, and rescreening on an organization-defined frequency and when individuals assume positions with higher risk. For covered entities and BAs, screening typically includes identity verification, criminal background checks scaled by PS-2 tier, and healthcare-specific checks such as OIG LEIE / SAM exclusions and license validation for clinical roles.
Ensure people receive ePHI system or facility access only after screening appropriate to position risk — and that elevated or long-tenured access is periodically revalidated.
How this control shows up in healthcare and HIPAA-covered environments.
Agency nurse needs EHR access same week. PS-3 checklist confirms identity, license, and exclusion screening completed (or agency attestation accepted under BAA) before credentials issue.
Promotion triggers rescreen and deeper package before privileged AD/EHR admin rights activate — PS-3 ties to PS-2 tier change.
Monthly LEIE recheck flags a billing specialist. Access is suspended pending investigation — showing rescreening is not only at hire.
HIPAA workforce clearance is frequently tested by comparing hire dates to access dates and asking for exclusion-list processes. Missing pre-access screens are high-visibility findings.
How this NIST control supports HIPAA Security Rule expectations.
Scale to PS-2 risk. Volunteers with no ePHI/system access may need lighter checks; those charting or transporting records need more.
PS-2 sets position risk; PS-3 applies the matching screening package before and during access.
Only where justified by role risk and lawful under applicable employment rules — document the rationale for finance/privileged roles if used.
Related controls that commonly accompany PS-3.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.