Skip to main content

Procedures for Establishing User Access Controls to Electronic Protected Health Information

Our emphasis for this paper is on the technical implications of database user access controls. This paper presents a practical case where three separate agencies, each representing a different aspect of health care, intend to share electronic protected health information (ePHI) with the goal of developing better outcome measures and improved access to care for their beneficiary population. The main entity, GIAC Health, must establish technical safeguards for role-based user access to this database. Access must be compliant with HIPAA regulations for privacy and security, supportable with policy, and able to be managed and monitored with the tools currently available in the technical environment.

1475 (PDF, 2.84MB)

14 Nov 2004
ByBarbara Filkins
Share
All papers are copyrighted

No re-posting of papers is permitted