(a)(1) Standard: Access control. Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights as specified in § 164.308(a)(4).
The Access control standard includes four (4) implementation specifications:
- (i) Unique user identification (Required).
- (ii) Emergency access procedure (Required).
- (iii) Automatic logoff (Addressable).
- (iv) Encryption and decryption (Addressable).