data-access-governance

Installation
SKILL.md

Data Access Governance

Overview

Establish and enforce comprehensive data access governance for protected health information (PHI) across electronic systems by implementing role-based access control (RBAC), minimum necessary standards, audit logging, anomaly detection, and break-the-glass procedures. HIPAA's Security Rule (45 CFR 164.312(a)) requires access controls as a technical safeguard, and the Privacy Rule (45 CFR 164.502(b)) mandates minimum necessary use and disclosure. This skill operationalizes these requirements into a practical governance framework that balances robust PHI protection with the clinical workflow efficiency needed for patient care delivery.

When to Use

  • Designing or reviewing role-based access control frameworks for EHR and clinical systems
  • Conducting periodic user access reviews and recertification
  • Investigating suspected unauthorized access to patient records (snooping)
  • Implementing minimum necessary standards for PHI access
  • Designing break-the-glass procedures for emergency access
  • Responding to OCR audit findings related to access controls
  • Managing access changes for new hires, role changes, and terminations
  • Evaluating access control capabilities during system selection or implementation

Required Inputs

Installs
1
GitHub Stars
1
First Seen
Jun 22, 2026
data-access-governance — goldenzero/skills