164.308(a)(3) Workforce Security

Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information, as provided under paragraph (a)(4) of this section, and to prevent those workforce members who have access under paragraph (a)(4) of this section from obtaining access to electronic protected health information.

Implementation Specification Description
164.308(a)(3)(ii)(A) Authorization and Supervision (Addressable)

Implement procedures for the authorization and supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.

164.308(a)(3)(ii)(C) Termination Procedures (Addressable)

Implement procedures for terminating access to electronic protected health information when the employment of a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(B) of this section.