45 CFR § 164.312(a)
Establishes technical controls to limit ePHI access to authorized persons and software. Covers unique user identification, emergency access procedures, automatic logoff, and encryption and decryption of data at rest.
Sample Preview
Version 1.0·Effective [EFFECTIVE DATE]·Approved by [PRIVACY/SECURITY OFFICER NAME]
This policy establishes the technical access control measures that [PRACTICE NAME] implements to ensure that only authorized persons and software programs have access to ePHI. It addresses the four implementation specifications: unique user identification, emergency access procedure, automatic logoff, and encryption and decryption.
This policy applies to all electronic information systems that create, receive, maintain, or transmit ePHI at [PRACTICE NAME], including EHR systems, practice management software, patient portals, email, file servers, cloud services, VPNs, and any other system or application through which ePHI is accessed. It applies to all workforce members and authorized third parties who access these systems.
[PRACTICE NAME] shall implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software programs that have been granted access rights as specified in 45 CFR § 164.312(a). Access controls shall include unique user identification, emergency access procedures, automatic logoff, and encryption/decryption mechanisms.
Access Control: The ability or means to limit, direct, or permit access to resources based on a user's identity and authorization level.
Unique User Identification: A unique name or number assigned to each user for identifying and tracking user identity within an information system.
Emergency Access Procedure: A documented procedure for obtaining access to necessary ePHI during an emergency, when normal access controls may not be functional.
Automatic Logoff: Electronic mechanisms that terminate a session after a predetermined period of inactivity.
Encryption: The use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a decryption key.
while we’re in beta
A professional, CFR-referenced policy template, ready to customize for your practice. Free during the beta.
Free while we’re in beta
Need more than one?
The Complete HIPAA Policy Library — every policy, checklist, and review template. Free while we’re in beta.
Free while we’re in beta
Templates require customization and legal review before adoption. Not legal advice. See full disclaimer.