data-access-governance
Installation
SKILL.md
Data Access Governance
Overview
Establish and enforce comprehensive data access governance for protected health information (PHI) across electronic systems by implementing role-based access control (RBAC), minimum necessary standards, audit logging, anomaly detection, and break-the-glass procedures. HIPAA's Security Rule (45 CFR 164.312(a)) requires access controls as a technical safeguard, and the Privacy Rule (45 CFR 164.502(b)) mandates minimum necessary use and disclosure. This skill operationalizes these requirements into a practical governance framework that balances robust PHI protection with the clinical workflow efficiency needed for patient care delivery.
When to Use
- Designing or reviewing role-based access control frameworks for EHR and clinical systems
- Conducting periodic user access reviews and recertification
- Investigating suspected unauthorized access to patient records (snooping)
- Implementing minimum necessary standards for PHI access
- Designing break-the-glass procedures for emergency access
- Responding to OCR audit findings related to access controls
- Managing access changes for new hires, role changes, and terminations
- Evaluating access control capabilities during system selection or implementation