Workforce Termination Procedures, v1.0

Specifies that a health care related organization must implement procedures for terminating access to electronic protected health information when the employment of a workforce member ends or as required by applicable regulations.

Assessment Step

1
Access Termination (AccessTermination)
Does the covered entity or business associate implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(B) of section 164.308?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Terminate Access
The covered entity or business associate must implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in section 164.308, paragraph (a)(3)(ii)(B) (Workforce Clearance Procedures).
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(3)(ii)(C)
HIPAA-Security-Rule
45 CFR Section 164.306