Access & identity
Who can reach systems containing ePHI, and can the practice explain why that access still fits the person’s role?
Staff moves, shared workflows, vendor accounts, privileged roles, and incomplete offboarding can make the account list different from the practice’s intended access model.
HIPAA Security Rule access-control and workforce-access provisions require deliberate access decisions. Specific configurations must fit the practice’s systems, risks, and documented policies.
See the HHS Security Rule summary and current 45 CFR Part 164, Subpart C.
- User and privileged-account inventory
- MFA coverage and exception notes
- Role and system-access approvals
- Joiner, mover, and leaver records
Practice leadership approves access and policy. HealthDesk can map accounts, settings, and gaps. Vendors explain their access paths. A compliance or legal advisor interprets obligations where needed.
Bring the current staff list, critical-system list, vendor access list, and any recent role or termination changes.

