Administrative
Workforce clearance, authorisation, sanctions, training and termination procedures. Written policy is the requirement; automated joining, moving and leaving is what makes the policy true on any given Tuesday.
In a hospital the difficult part of access control is not saying no. It is saying yes fast enough that nobody reaches for a shared login, narrowly enough to satisfy minimum necessary, and with enough of a record left behind to explain the decision months later.
The security rule divides its requirements into administrative, physical and technical safeguards. Identity carries a large share of the first and the third, and none of the second.
Workforce clearance, authorisation, sanctions, training and termination procedures. Written policy is the requirement; automated joining, moving and leaving is what makes the policy true on any given Tuesday.
Unique user identification, emergency access procedure, automatic logoff, audit controls, authentication of the person requesting data. This is the list an identity platform is measured against.
Facility access, device and media controls. Not our layer — with one intersection worth naming: the shared clinical workstation, where physical and logical access blur into the same problem.
Minimum necessary and clinical urgency pull in opposite directions, and the resolution is not a policy sentence: it is a path that is fast, narrow, short and reviewed. Four gates, in that order.
A clinician who needs a record outside their normal scope declares why, in the flow, at the moment of access. No ticket, no phone call to a duty manager: the alternative to a fast path is a shared login that somebody wrote on a whiteboard.
The elevation covers the patient in front of them rather than the department. Scope is the difference between an emergency provision and a permanent second role that never gets reviewed.
Emergency access with no end time becomes standing access within a week. The session carries its own expiry, and ending it does not depend on anyone remembering.
Somebody accountable sees that it happened, with the stated reason next to the record touched. Reviewing every emergency access is feasible precisely because the fast path is scoped and short.
Remove any one of the four and the pattern degenerates. Fast without narrow is a second account; narrow without expiry is a permanent role; all three without review is an audit finding waiting for its date.
A hospital runs on populations with wildly different lifespans, and the identity system usually models only the first one properly.
The easy population, and still the one where role changes accumulate: a nurse who moved ward, a consultant who covered another unit for a month three years ago.
Access follows a rotation calendar that HR does not hold. It should end when the placement ends, which means the placement has to be the thing that grants it.
Onboarded at short notice by someone who needs them working immediately. The population where credentials get shared, because provisioning was slower than the shift.
Imaging maintenance, an EHR integrator, a remote application specialist. Contractual obligations exist on paper; what matters technically is scoped, time-boxed access with an attributable identity behind it.
The integrations moving records between systems. No manager, no leaving date, and standing access to more data than any individual clinician.
Unique identification is the requirement everything else rests on: an audit trail is worth nothing if the actor is a workstation login four people know. Fast, phishing-resistant authentication is what makes individual accounts survive contact with a shift.
Lifetime, scope and conditions belong to the session, and can be shortened or terminated from outside the application — on a shared clinical workstation, that is the control that stops the previous user's access being inherited.
Access granted from the system that actually knows — HR, the rota, the placement register — and removed the same way. Future-dated events become scheduled work, which is how a locum's access ends on the day it should.
It is not a covered entity and does not process clinical records: it governs who may reach the systems that hold them, and keeps the history of those decisions. Whether a business associate agreement is needed, and what it must cover, depends on the deployment — including whether the platform runs in Monokee Cloud or on your own infrastructure.
This page describes how an identity layer supports safeguards under the US Health Insurance Portability and Accountability Act. It is not legal advice and not a statement of compliance: covered entity and business associate obligations, risk analysis and the agreements that govern vendor access remain the responsibility of the organisation.
It exists in every hospital, and it exists for a reason. Replacing it starts with making the individual path faster than the shared one.
Talk to an expert