The HIPAA IAM Checklist: Access Controls Auditors Actually Look For
Most HIPAA Security Rule risk assessments don't fail on exotic findings — they fail on access control basics that were never fully implemented or never revisited after go-live. If you're preparing for an assessment, or just want to know where an auditor's attention will land first, start here.
1. Role-based access, mapped to job function
The Security Rule's minimum necessary standard means access should map to job function, not convenience. Auditors will ask for your role definitions and expect to see access provisioned against them — not a history of one-off requests granted because someone was in a hurry.
- Document standard roles for clinical, administrative, and IT staff
- Map each role to the specific systems and data it requires
- Flag and remediate any account with access outside its mapped role
2. A real joiner/mover/leaver process
Access that isn't revoked on termination is one of the most common findings in a HIPAA audit — and one of the easiest to fix with a documented process instead of an informal one.
- Provisioning tied to HR onboarding, not a verbal request to IT
- Access changes triggered automatically on role change
- De-provisioning within a defined window of termination — same day, ideally
3. Periodic access recertification
Access reviews aren't a one-time project. Auditors expect evidence of a recurring cycle — typically quarterly or semi-annually for systems holding PHI — where a manager or system owner actively confirms each person's access is still needed.
4. Multi-factor authentication on anything that touches PHI
MFA is no longer optional for remote access, administrative accounts, or any system storing or transmitting PHI. Where it isn't yet universal, document a remediation timeline — an active plan is defensible in a way that silence is not.
5. Privileged and administrative account controls
- Admin accounts separate from standard user accounts (no shared logins)
- Privileged access logged and reviewed independently
- Break-glass / emergency access procedures documented and tested
6. Audit logging that's actually reviewed
Logging access to PHI is necessary but not sufficient — the Security Rule expects evidence that logs are reviewed, not just retained. If nobody can show you the last time PHI access logs were reviewed, that's a finding waiting to happen.
Where this usually goes wrong
In our experience, the gap is rarely a missing tool — most healthcare organizations already have IAM technology capable of doing this. The gap is process: roles that were never formally defined, a de-provisioning step that depends on someone remembering, or a recertification cycle that exists on paper but hasn't actually run in over a year. That's a process and governance problem before it's a technology problem, which is exactly where an outside assessment tends to be most useful — a fresh look at what's actually happening versus what the policy says should happen.