Clinical Data Access Audit and Hardening
A hospital or clinic already running a clinical system — the Hospital Operations & Patient Flow Platform, a purchased product, or a mixture — where access was granted as people joined and never reviewed, and where nobody can say who has looked at a given patient's record.
The problem
Clinical records carry confidentiality obligations, and the facility cannot currently demonstrate who can see what, who has seen what, or what would happen if a record were exposed.
In scope
- Access review against roles
- Logging assessment
- Break-glass procedure design
- Retention position
- Breach readiness
- Remediation plan with effort estimates
- Retest
Out of scope
- Building or replacing the clinical system.
- Certifying compliance — Afivox assesses and remediates, it does not issue certification.
- Legal opinion on the facility's regulatory obligations.
What this would cover
Grouped by module — open the ones you want to read.
Access inventory
- Every account, every role, every permission, mapped against who actually needs it; dormant and orphaned accounts identified
Role rationalisation
- A proposed permission matrix where most staff can do less than they can today, with the clinical justification for each grant
Logging assessment
- Whether record views, not only edits, are logged; whether logs are tamper-evident; whether anyone reads them
Break-glass design
- Emergency access that is permitted, loudly logged, and routed into a review report; plus the process commitment that someone actually reads it
Data at rest and in transit
- Encryption position, backup encryption, and a tested restore, because an untested backup is a hope
Retention and disposal
- How long records are kept and what happens to them afterwards, aligned to the facility's own obligations
Third-party access
- HMO portals, billing vendors, IT contractors, equipment suppliers, each an access path usually forgotten
Breach readiness
- Who is called, in what order, within what time; a one-page procedure rather than a policy nobody will read at 2am
Remediation plan
- Findings ranked by exploitability and by clinical impact, each with a fix and an effort estimate
Retest
- Verification that agreed fixes actually landed
Data model
- Not a build. Deliverables are documents: access inventory, permission matrix, findings register, remediation plan, breach procedure, retest report.
Invariants
- Not applicable — this is an assessment engagement. The one structural rule: findings are ranked by exploitability and impact, never listed alphabetically or by tool output order.
Offline behavior
Not applicable.
Hard trade-offs
The difficult decisions, stated plainly — not trimmed for length.
An access review names people, and some of those people will be senior.
The most common real finding in a facility of this kind is that a long-serving administrator has accumulated access far beyond their role, often because they were helpful during a crisis years ago. Removing it is a political act, not a technical one. Afivox reports findings to the engaging authority confidentially and does not adjudicate internal consequences — and the engagement letter should say so before work starts.
Break-glass access only works if someone reviews the report.
The system can generate it; only the facility can commit to reading it. A remediation plan that depends on a review nobody performs should be marked as unmitigated rather than closed.
Regulatory note
[FILL: confirm the facility's specific obligations — NDPA, any HMO contractual requirements, and professional body guidance — before scoping. Afivox assesses against the facility's stated obligations and does not offer legal advice on what they are.]
End state
What would be true about their day once this is running.
- The facility can say who can see what, and prove who has seen what.
- Access reflects current roles rather than historical accumulation.
- Emergency access is possible, logged and reviewed.
- Backups restore, tested rather than assumed.
- There is a one-page procedure for the day something goes wrong.
Let's map how your operation actually runs.
One session. We look at what's breaking, and what we'd build around it — whether or not you hire us afterward.
Start the operations review