14.3 Privacy and Security Policies, Access, and Safeguards
Key Takeaways
- Task E.1 turns law into policy: confidentiality, privacy, security, availability, and integrity become written procedures with owners, sanctions, and evidence—not a once-a-year slide deck.
- Privacy governs authorized use and disclosure of PHI; security governs the CIA of ePHI. You need both. A locked server that still auto-discloses a full chart is a privacy miss.
- Task E.3 implements access as unique IDs, role-based least privilege, joiner-mover-leaver, recertification, and audited break-the-glass. Shared “nurse” logins and standing God mode fail the task.
- Task E.4 uses the HIPAA Security Rule’s three safeguard categories: administrative, physical, and technical. HIMSS examples include secured servers, unattended workstations, and two-factor authentication.
- Addressable specifications still require a documented, risk-based decision. Do not memorize stale civil-money-penalty dollar tables; OCR tiers are inflation-adjusted and published by HHS.
14.3 Privacy and Security Policies, Access, and Safeguards
Quick Answer: Task E.1 writes and implements policies for confidentiality, privacy, security, availability, and integrity. Task E.3 turns those policies into user access—unique IDs, RBAC, least privilege. Task E.4 places administrative, physical, and technical safeguards on assets (secured servers, unattended workstations, two-factor authentication). Law without a control is a binder.
Chapter 3 taught who is regulated and which HIPAA rule applies. Chapter 5.3 put CIA on the network, identity, and endpoint fabric. This section is Domain 3’s operating system for those ideas: the policy, the access model, and the safeguard category you name on an exam stem. Domain 3 is 30% of CPHIMS; E-tasks are how implementations stay legal after the project team leaves.
Policies that actually run (E.1)
HIMSS lists five qualities together on purpose: confidentiality, privacy, security, availability, and integrity. Do not collapse them.
- Privacy is about authorized use, disclosure, and individual rights (Privacy Rule): minimum necessary, treatment / payment / operations, authorizations, patient access.
- Security is about protecting ePHI so those authorizations are enforceable (Security Rule): CIA controls.
- Confidentiality is the CIA goal that only authorized people and systems see the data.
- Integrity is the CIA goal that the data are not improperly altered.
- Availability is the CIA goal that care can use the data when needed—including during incidents.
A policy set that only says “do not share passwords” has not met E.1. CPHIMS-ready policies are implemented procedures: who does what, with which system, how often, what evidence is kept, and what sanction follows a violation. Typical packet:
| Policy / procedure | What it operationalizes | Evidence you can show |
|---|---|---|
| Notice of privacy practices and patient-rights workflows | Privacy Rule individual rights | Access, amendment, and restriction tickets |
| Minimum necessary and role design | Privacy + access management | Role catalog, interface filters |
| Acceptable use and sanction | Workforce security | Signed ack, discipline log |
| Access provisioning and recertification | E.3 | HR feed, quarterly manager attestations |
| Incident response and breach assessment | Security incident + Breach Notification Rule | Playbook, four-factor notes, clocks from Chapter 3 |
| Device, media, and workstation use | Physical + technical | Encryption inventory, wipe logs |
| Contingency / downtime | Availability | Restores, tabletop minutes |
| Business associate management | BAAs, not NDAs | Executed BAA list, vendor access reviews |
Policies need an owner, a review cadence, and a path into training. A PDF on SharePoint that nobody can find during an OCR desk review is not implemented. Do not invent a dollar penalty on the exam if a stem asks about enforcement; HHS civil money penalty tiers are inflation-adjusted and published by OCR. The professional move is the control and the documentation, not a memorized 2013 figure.
Addressable Security Rule specifications still require a documented, risk-based decision to implement, use an equivalent, or explain why neither is reasonable (Chapter 3). Addressable is not a skip code you write into policy.
User access controls (E.3)
Access is how policy becomes a login. Define and implement controls according to the written procedures, not according to whoever yelled last.
Unique user identification is required. Shared “ED nurse,” “radiology,” or “front desk” accounts destroy accountability and audit. Temporary badges that map to a named, time-limited ID are the alternative—not a communal password on a sticky note.
Role-based access control (RBAC) assigns permissions to a job role plus context (unit, service, facility), not to a charismatic individual. Least privilege means the role gets what the job needs and nothing decorative: a scheduler does not need a problem-list edit; a coder does not need e-prescribe; a vendor engineer does not need a standing production clinician role.
Joiner-mover-leaver is the lifecycle:
- Joiner — access starts from HR or medical-staff status, not from a friend’s clone of an old account.
- Mover — when a nurse becomes a case manager, the old inpatient role comes off the same week. Additive access is how God mode is born.
- Leaver — termination or end of rotation disables the ID the same day, including VPN, email, EHR, and badge-triggered applications. Orphaned accounts are a recurring investigation theme.
Break-the-glass (emergency access) is a logged, justified elevation, not a second home page. Recertify privileged and high-risk roles on a calendar. Review VIP and workforce-patient charts. Service accounts are owned, vaulted, and not used by humans.
Multi-factor (two-factor) authentication is the HIMSS-named technical example that increasingly applies to remote, privileged, and ePHI access. MFA is not a substitute for least privilege: a stolen-but-MFA-gated God-mode account is still too much power.
Provisioning tickets should cite the policy role, not “same as Jane.” If Jane was over-permissioned, you just cloned a finding.
Administrative, physical, and technical safeguards (E.4)
The Security Rule organizes safeguards into three families. Task E.4 asks you to assess and implement them so assets are actually protected. HIMSS’s examples are concrete: servers secured, unattended computers, two-factor authentication.
Administrative safeguards (45 CFR 164.308) are the management controls: assigned security official, risk analysis and risk management, sanction policy, activity review, workforce clearance, information-access management, awareness training, incident procedures, contingency plan, periodic evaluation, and business-associate contracts. If the only “admin control” you can name is a firewall brand, you are in the wrong family.
Physical safeguards (45 CFR 164.310) protect buildings, rooms, and devices: facility access (badges, visitor logs, locked data centers and IDF closets), workstation use (where and how a screen may be used), workstation security (physical protection of the device), and device/media controls (receipt, reuse, disposal, backup movement). A secured server is a physical control: cages, cameras, limited badge access, no unlabeled cart in a hallway. An unattended workstation in a hallway or ED pod is a physical-plus-procedural problem: privacy screens, automatic lock, cable locks where theft is plausible, and a rule that walking away means locking—not “the unit is busy.”
Technical safeguards (45 CFR 164.312) are the system controls: unique user ID, emergency access procedure, automatic logoff, encryption/decryption, audit controls, integrity controls, person or entity authentication, and transmission security. Two-factor authentication, automatic logoff on shared clinical workstations, and unique IDs live here. Encryption of portables and backups remains the operational default even though some specs are addressable (Chapter 5.3).
Map the HIMSS examples on purpose:
- Servers secured → primarily physical (facility access, device/media), supported by technical hardening and administrative risk analysis.
- Unattended computers → physical workstation use/security plus technical automatic logoff and screen lock, plus administrative training and sanctions when people walk away from an open chart.
- Two-factor authentication → technical authentication / access control, required by policy (administrative) and useless if the second factor is a shared token in a drawer.
Exam stems that offer “buy a named appliance” as the only answer are usually wrong. Stems that offer “write a policy and stop” without implementing the control are also wrong. E.4 is assess and implement.
Scenarios and exam traps
Scenario. A hallway computer in pre-op shows a full surgical schedule after the nurse walks to the next bay. Automatic logoff is set to 24 hours “because anesthesia complained.” This is an unattended-workstation failure across physical workstation use, technical automatic logoff, and administrative training. Redesign the timeout with clinicians; do not pretend privacy screens alone are enough.
Scenario. A clinic manager clones her access for a new registrar “so she can help with everything.” E.3 wants a registrar role with least privilege, not a cloned manager. Recertify the manager’s own access while you are there.
Scenario. Servers for a clinic EHR sit in an unlocked broom closet next to the back door. Technical encryption is on. E.4 still fails physical facility access. Lock, badge, and inventory the room.
Scenario. Remote ICU coverage goes live with passwords only because “MFA will slow nights.” Two-factor authentication is the HIMSS-named control for a reason. Pair MFA with a break-glass path that is audited, not with a blanket exemption.
Watch these traps:
- Calling addressable specifications optional in the policy.
- Treating privacy and security as synonyms.
- Shared logins, cloned access, and standing emergency-access pools.
- Naming only a firewall when the stem is an unattended workstation or an unlocked server room.
- Inventing a specific OCR dollar penalty instead of naming the control and the documentation duty.
- Writing a beautiful policy that no joiner-mover-leaver process implements.
E.1, E.3, and E.4 are the standing design. Section 14.4 is how you find what is still weak, who owns the weakness, how data themselves are controlled, and how you keep proving it after go-live.
A pre-op hallway workstation is left logged into the EHR with the next patient’s chart visible while the nurse steps away. Automatic logoff is 24 hours. Which safeguard reading is CPHIMS-correct?
A clinic manager asks IT to “make the new registrar just like me” so the registrar can cover phones, billing edits, and the manager’s quality workbench. What E.3 design should you implement instead?
Leadership wants a single label for three findings: an unlocked server closet, missing two-factor authentication on the VPN, and no assigned security official. Which mapping matches the Security Rule families?