HIPAA

Granting access in thirty seconds, and justifying it afterwards

In a hospital the difficult part of access control is not saying no. It is saying yes fast enough that nobody reaches for a shared login, narrowly enough to satisfy minimum necessary, and with enough of a record left behind to explain the decision months later.

Where identity sits

Three sets of safeguards, one of them mostly access

The security rule divides its requirements into administrative, physical and technical safeguards. Identity carries a large share of the first and the third, and none of the second.

Administrative

Workforce clearance, authorisation, sanctions, training and termination procedures. Written policy is the requirement; automated joining, moving and leaving is what makes the policy true on any given Tuesday.

Technical

Unique user identification, emergency access procedure, automatic logoff, audit controls, authentication of the person requesting data. This is the list an identity platform is measured against.

Physical

Facility access, device and media controls. Not our layer — with one intersection worth naming: the shared clinical workstation, where physical and logical access blur into the same problem.

Emergency access

Break the glass, and put it back

Minimum necessary and clinical urgency pull in opposite directions, and the resolution is not a policy sentence: it is a path that is fast, narrow, short and reviewed. Four gates, in that order.

01

Asked for, not routed

Seconds

A clinician who needs a record outside their normal scope declares why, in the flow, at the moment of access. No ticket, no phone call to a duty manager: the alternative to a fast path is a shared login that somebody wrote on a whiteboard.

02

Granted narrowly

This record, not this system

The elevation covers the patient in front of them rather than the department. Scope is the difference between an emergency provision and a permanent second role that never gets reviewed.

03

Expires by itself

Minutes to hours

Emergency access with no end time becomes standing access within a week. The session carries its own expiry, and ending it does not depend on anyone remembering.

04

Reviewed afterwards

Next working day

Somebody accountable sees that it happened, with the stated reason next to the record touched. Reviewing every emergency access is feasible precisely because the fast path is scoped and short.

Remove any one of the four and the pattern degenerates. Fast without narrow is a second account; narrow without expiry is a permanent role; all three without review is an audit finding waiting for its date.

Who needs access

The permission is usually right. The duration never is.

A hospital runs on populations with wildly different lifespans, and the identity system usually models only the first one properly.

Permanent clinical staff

Years, reviewed by role

The easy population, and still the one where role changes accumulate: a nurse who moved ward, a consultant who covered another unit for a month three years ago.

Rotating residents and students

Weeks per placement

Access follows a rotation calendar that HR does not hold. It should end when the placement ends, which means the placement has to be the thing that grants it.

Agency and locum cover

Shifts, sometimes one

Onboarded at short notice by someone who needs them working immediately. The population where credentials get shared, because provisioning was slower than the shift.

Third-party support and vendors

The length of the intervention

Imaging maintenance, an EHR integrator, a remote application specialist. Contractual obligations exist on paper; what matters technically is scoped, time-boxed access with an attributable identity behind it.

Service accounts and interfaces

As long as the interface exists

The integrations moving records between systems. No manager, no leaving date, and standing access to more data than any individual clinician.

How Monokee approaches it

Individual identities, short sessions, evidence by default

One identity per person, including at 3 a.m.

Unique identification is the requirement everything else rests on: an audit trail is worth nothing if the actor is a workstation login four people know. Fast, phishing-resistant authentication is what makes individual accounts survive contact with a shift.

Sessions that end where the shift does

Lifetime, scope and conditions belong to the session, and can be shortened or terminated from outside the application — on a shared clinical workstation, that is the control that stops the previous user's access being inherited.

Joiners, movers and leavers on clinical time

Access granted from the system that actually knows — HR, the rota, the placement register — and removed the same way. Future-dated events become scheduled work, which is how a locum's access ends on the day it should.

What Monokee is not

It is not a covered entity and does not process clinical records: it governs who may reach the systems that hold them, and keeps the history of those decisions. Whether a business associate agreement is needed, and what it must cover, depends on the deployment — including whether the platform runs in Monokee Cloud or on your own infrastructure.

Four things to keep in view

Before scoping the work

  • The security rule names unique user identification, emergency access, automatic logoff and audit controls — four requirements decided almost entirely at the identity layer.
  • Workforce clearance and termination procedures are administrative safeguards, which in practice means joiner-mover-leaver automation with evidence attached.
  • Most breached records arrive through third parties and connected services rather than the core clinical system, which makes vendor access a first-order control rather than procurement paperwork.
  • European healthcare providers face the same access problems under a different law. See the GDPR page →

This page describes how an identity layer supports safeguards under the US Health Insurance Portability and Accountability Act. It is not legal advice and not a statement of compliance: covered entity and business associate obligations, risk analysis and the agreements that govern vendor access remain the responsibility of the organisation.

Bring us the workstation four people log into

It exists in every hospital, and it exists for a reason. Replacing it starts with making the individual path faster than the shared one.

Talk to an expert