Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: No least-privilege; no access reviews · 164.308(a)(4) Access Mgmt; 164.312(a) Access Control
Exploits: No access controls on shares · 164.312(a) Access Control; 164.514(d)
Exploits: No or weak MFA; reused passwords · 164.312(d) Authentication; 164.308(a)(5) Training
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[password manager]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] grants, manages, and revokes access to information systems, applications, devices, and the electronic protected health information (ePHI) they contain, so that access is limited to authorized workforce members on a least-privilege, need-to-know basis. It satisfies the access-control requirements of the HIPAA Security Rule at 45 CFR §§ 164.308(a)(3), 164.308(a)(4), 164.308(a)(5)(ii)(D), and 164.312(a)/(d).
This Policy applies to all workforce members (employees, contractors, interns, and volunteers), business associates, and any other party granted access to [Organization] systems, and to all system components (applications, endpoints, cloud services, and infrastructure) that create, receive, maintain, or transmit ePHI. Workforce members must acknowledge this Policy in writing before access is granted and at least annually thereafter.
See where your organization stands on the controls this template cites.
Join UsAccess to ePHI and supporting systems is granted only as required to perform an assigned role. [Organization] defines role-based access (RBAC) categories for each system and data store, and a workforce member receives the minimum access necessary for their role. Administrative privilege is limited to users with a documented business need and must not include the ability to alter or delete audit/log data.
Every user is assigned a unique identifier so that all activity is traceable to an individual. Shared, group, or generic accounts are prohibited, and default vendor accounts are disabled or renamed before a system is placed in service. Identity is verified before access is granted and before any security-sensitive support request (e.g., password reset) is honored.
MFA is required wherever it is supported, and always for: remote access, the [cloud productivity & storage suite], the [identity provider / single sign-on], source-control and production systems, and any system holding ePHI. Authentication combines at least two factors: something you know (password/PIN), something you have (device, token), or something you are (biometric).
Passwords protecting access to ePHI must meet, at minimum:
Use of a [password manager] is encouraged. Routine forced expiration is not required for MFA-protected user accounts (consistent with current NIST guidance); credentials are rotated on compromise, on offboarding of anyone who knew a shared secret, and per a defined interval for privileged or shared accounts. [Organization] may strengthen any item above.
Access is granted only after documented authorization by the [Security Official] (or a designated approver) based on role. Requests for access beyond a role's standard set must include a business justification. Account creation, enablement, modification, disablement, and removal follow the documented process in the companion Access Control Procedures, are aligned with HR joiner/mover/leaver events, and are tracked in a [ticketing system]. Supervision is applied to workforce members whose roles involve access to ePHI.
[Organization] ensures that workforce members have appropriate access and that those who should not have access to ePHI are prevented from obtaining it. Access is revoked promptly upon termination or role change: targeted at the time of separation and no later than [24 hours] after notification. (Pre-hire screening and sanctions are governed by the Workforce Security, Training & Sanctions Policy.)
The [Security Official] reviews access rights against role and least-privilege at least annually, and [quarterly] for systems containing ePHI, and on any role change. Findings and any resulting changes are documented. Accounts inactive beyond [90 days] are disabled.
Systems and devices that access ePHI lock or terminate the session after a defined period of inactivity ([15 minutes] for endpoints). Users must lock or log off unattended devices; a password/credential is required to re-establish access.
A documented emergency ("break-glass") procedure allows designated personnel to obtain necessary ePHI during an emergency (e.g., outage of the normal access path or staff unavailability). Break-glass use is pre-authorized to named roles, logged, and reviewed after the fact by the [Security Official].
Where supported, systems lock an account after [5] consecutive failed attempts within [30 minutes] for at least [30 minutes]; privileged accounts require administrator unlock, and the administrator is notified.
High-risk processes identified by the risk-management process (e.g., production deployments, financial transactions, major infrastructure changes) require separation of duties so that no single individual controls the entire process.
If [Organization] performs health-care clearinghouse functions as part of a larger organization, it implements policies and procedures that protect that ePHI from unauthorized access by the larger organization. (If not applicable, mark N/A and document why.)
[Security Official]: owns this Policy; approves access standards, authorizations, and exceptions; conducts access reviews.Access Control Procedures · Workforce Security, Training & Sanctions Policy · Audit Controls & Activity Review Policy · Security Incident Response Policy.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.312(a)(1) | Access Control | §1, §11 |
| 164.308(a)(4)(i) | Information Access Management | §1, §5 |
| 164.312(a)(2)(i) | Unique User Identification | §2 |
| 164.312(d) | Person or Entity Authentication | §2, §3 |
| 164.308(a)(5)(ii)(D) | Password Management | §4 |
| 164.308(a)(4)(ii)(B) | Access Authorization | §5 |
| 164.308(a)(4)(ii)(C) | Access Establishment & Modification | §5, §7 |
| 164.308(a)(3)(ii)(A) | Authorization and/or Supervision | §5 |
| 164.308(a)(3)(i) | Workforce Security | §6 |
| 164.308(a)(3)(ii)(C) | Termination Procedures | §6 |
| 164.312(a)(2)(iii) | Automatic Logoff | §8 |
| 164.312(a)(2)(ii) | Emergency Access Procedure | §9 |
| 164.308(a)(4)(ii)(A) | Isolating Clearinghouse Functions | §12 |
Reviewed at least annually by the [Security Official] and after any significant change to the ePHI environment. v1.0.