Health Information Management

Question of the Week: How does role-based access work?

HIPAA Weekly Advisor, September 3, 2001

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: The HIPAA security requirements address role-based access. How does role-based access work?

A: Access generally can be restricted based on three different ways:

1. Context-based access: based on the type of transaction
2. Role-based access: based on job or function (i.e., need to know)
3. User-based access: based on an individual's identity

Since a big concern identified in the 2001 Health Information Management Systems Society survey was internal threats to IT security, I would recommend access be restricted based on roles. Roles can be refined down to the document, database, or application level.

A physician may need to append information to a medical record, while a medical records clerk should be allowed to access the records but not add or change information. This approach is very useful if you want to allow all employees to access an application but restrict what information can be viewed or modified.

With role-based access, you need to authenticate the user, not just the machine that they are logging on from. This can be accomplished via tokens, smartcards, or biometrics. This segmented approach is more specific than defining access based on "groups" (e.g., all accounting).

The Computer-based Patient Record Institute has an excellent document which gives many examples of role-based access schemes. Exactly, how granular the role-based access needs to be depends on your organization. Keeping up with changes in titles, functions, and departmental changes to "roles" can be a daunting task.

Go to http://www.cpri-host.org/toolkit/toc.html for more information on the CPRI Toolkit.

Editor's note: Answered by Jon Bogen, president of HealthCIO Inc. in Duxbury, MA. If you have a question, write to BOH, P.O. Box 1168, Marblehead, MA 01945, or send an e-mail to BOH editor Brian Driscoll at bdriscoll@hcpro.com.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles