Access control and sign-in
Only the right people should reach ePHI, each under their own account, with a reliable way to confirm who is signing in. In practice: unique user accounts, strong authentication such as MFA, and automatic logoff.
Access control and sign-in at a glance
HIPAA access control means only authorized people or software can reach electronic protected health information. The Security Rule requires unique user identification and an emergency access procedure, makes automatic logoff and encryption addressable, and separately requires procedures to verify that whoever signs in is who they claim to be. For cloud tools, that translates into individual accounts, enforced multifactor authentication and least-privilege permissions.
| Rules | 45 CFR 164.312(a)(1) and 164.312(d) |
|---|---|
| Required | Unique user IDs, emergency access procedure, person or entity authentication |
| Addressable | Automatic logoff, encryption and decryption |
| In practice | One account per person (required); strong authentication such as MFA and role-based permissions (recommended, risk-based) |
| Check in tools | Can an admin enforce MFA and remove access instantly? |
The access control standard (164.312(a)(1)) requires technical policies and procedures so that only people or software granted access rights can reach electronic PHI. Its implementation specifications include unique user identification and an emergency access procedure (both required), plus automatic logoff (addressable). A separate standard, person or entity authentication (164.312(d)), requires procedures to verify that whoever is signing in is who they claim to be.
What this looks like in a small organization
- One person, one account. Shared logins (“frontdesk@”) make it impossible to know who did what. Each staff member gets their own.
- Strong sign-in. The rule does not name a specific technology, but we recommend multi-factor authentication as the practical way to meet the authentication standard for cloud tools reachable from anywhere.
- Least privilege. Give people access to what their role needs, and remove it the day they leave.
- Automatic logoff on shared or unattended devices.
- Emergency access. Know how you would reach critical records if the usual person or system is unavailable.
What to check when choosing a tool
- Can you create separate accounts for every user on your plan?
- Can you enforce MFA for everyone, not just recommend it?
- Are there roles or permissions, so not everyone sees everything?
- Can an administrator remove access and sign a user out of all devices immediately?
Tools and services where this matters
- AI models and chat assistants →Tool
- Cloud storage and file sharing →Tool
- HIPAA email services →Tool
- HIPAA hosting and cloud platforms →Tool
- Telehealth and video visits →Tool
Guides
- HIPAA compliance checklist →A practical HIPAA checklist for small practices and business associates, with each item linked to the rule behind it — not a list of things to buy.
- HIPAA training →What HIPAA training has to cover, who needs it, how to structure a program for a small practice, and how to judge an online course.
Scenarios
Related requirements
Frequently asked questions
Does HIPAA require multifactor authentication?
The current rule requires procedures to verify the identity of anyone accessing ePHI but does not name a specific technology. For cloud services reachable from anywhere, we recommend enforced MFA as the practical way to meet that standard.
Can staff share a login?
No. Unique user identification is a required specification — shared logins make it impossible to tell who accessed what.