PS-3 Personnel Security

Personnel Screening

High Risk Moderate Medium Cost

PS-3 requires screening individuals prior to authorizing access to the system, and rescreening on an organization-defined frequency and when individuals assume positions with higher risk. For covered entities and BAs, screening typically includes identity verification, criminal background checks scaled by PS-2 tier, and healthcare-specific checks such as OIG LEIE / SAM exclusions and license validation for clinical roles.

Control Objective

Ensure people receive ePHI system or facility access only after screening appropriate to position risk — and that elevated or long-tenured access is periodically revalidated.

Implementation Guidance

  1. Define screening packages by PS-2 tier (standard hire vs privileged/admin vs clinical licensed).
  2. Complete required checks before provisioning IdP/EHR access; document interim access exceptions tightly.
  3. Include OIG LEIE, SAM, and applicable state exclusion lists for workforce who can affect billing or clinical systems.
  4. Verify professional licenses/credentials for roles that prescribe, code, or document care.
  5. Rescreen on defined cadence (e.g., every 2–3 years for High/Privileged) and on promotion into higher-risk positions.
  6. Extend equivalent screening expectations to contractors and staffing agencies via contract language.
  7. Protect screening results as confidential HR records; share only need-to-know clearance status with IT.
  8. Deny or delay access when checks fail; escalate to HR/compliance for adjudication.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Traveler nurse onboarding

Agency nurse needs EHR access same week. PS-3 checklist confirms identity, license, and exclusion screening completed (or agency attestation accepted under BAA) before credentials issue.

Helpdesk promoted to domain admin

Promotion triggers rescreen and deeper package before privileged AD/EHR admin rights activate — PS-3 ties to PS-2 tier change.

Exclusion list hit after hire

Monthly LEIE recheck flags a billing specialist. Access is suspended pending investigation — showing rescreening is not only at hire.

Best Practices

  • Gate account creation on clearance status in HRIS/IAM.
  • Use healthcare exclusion lists, not only criminal checks.
  • Rescreen on promotion and on a calendar for high-risk roles.
  • Contractually require staffing agencies to screen equivalently.
  • Separate clearance result from technical provisioning.
  • Track incomplete screens as open risk items.

Common Gaps & Violations

  • Accounts created before background check returns.
  • No OIG/exclusion screening for revenue-cycle staff.
  • Contractors never screened.
  • No rescreen when moving into privileged IT.
  • Screening policy exists but completion is not evidenced.

Required Documentation

  • Personnel screening procedure by risk tier
  • Screening checklist / vendor package specs
  • Pre-access clearance evidence samples
  • Rescreen schedule and completion logs
  • Contractor/agency screening requirements

How to Test & Validate

  1. Sample recent hires: clearance date precedes first EHR login.
  2. Verify LEIE/exclusion checks for billing and clinical samples.
  3. Confirm a privileged promotion had rescreen evidence.
  4. Review contractor onboarding for screening attestation.
  5. Check adjudication records for failed/flagged results.

Audit Considerations

HIPAA workforce clearance is frequently tested by comparing hire dates to access dates and asking for exclusion-list processes. Missing pre-access screens are high-visibility findings.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(B) Workforce Clearance Procedures — procedures to determine that access of a workforce member to ePHI is appropriate.
  • 164.308(a)(3) Workforce Security — authorization and supervision depend on trustworthy workforce assignment.
  • 164.530(b) Training — screening complements, not replaces, privacy/security training requirements.
  • 164.308(a)(1) Risk Management — insider risk is managed partly through screening depth.

Compliance Tips

  • Add a hard stop in IAM: no role assignment without clearance flag = Passed.
  • Automate monthly LEIE batch checks for active workforce.
  • Keep a one-page screening matrix by tier for assessors.

Frequently Asked Questions

Must every volunteer get a full criminal background check?

Scale to PS-2 risk. Volunteers with no ePHI/system access may need lighter checks; those charting or transporting records need more.

How does PS-3 relate to PS-2?

PS-2 sets position risk; PS-3 applies the matching screening package before and during access.

Are credit checks required?

Only where justified by role risk and lawful under applicable employment rules — document the rationale for finance/privileged roles if used.

References & Resources

  • NIST SP 800-53 Rev. 5 — PS-3
  • HHS OIG LEIE guidance
  • HIPAA § 164.308(a)(3)
  • Related controls: PS-2, PS-6, AC-2, IA-12, PE-2

Need Help Implementing PS-3?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.