Skip to content
Concept · Tier 4Layer

Clinical Data Access Audit and Hardening

A hospital or clinic already running a clinical system — the Hospital Operations & Patient Flow Platform, a purchased product, or a mixture — where access was granted as people joined and never reviewed, and where nobody can say who has looked at a given patient's record.

The problem

Clinical records carry confidentiality obligations, and the facility cannot currently demonstrate who can see what, who has seen what, or what would happen if a record were exposed.

In scope

  • Access review against roles
  • Logging assessment
  • Break-glass procedure design
  • Retention position
  • Breach readiness
  • Remediation plan with effort estimates
  • Retest

Out of scope

  • Building or replacing the clinical system.
  • Certifying compliance — Afivox assesses and remediates, it does not issue certification.
  • Legal opinion on the facility's regulatory obligations.

What this would cover

Grouped by module — open the ones you want to read.

Access inventory
  • Every account, every role, every permission, mapped against who actually needs it; dormant and orphaned accounts identified
Role rationalisation
  • A proposed permission matrix where most staff can do less than they can today, with the clinical justification for each grant
Logging assessment
  • Whether record views, not only edits, are logged; whether logs are tamper-evident; whether anyone reads them
Break-glass design
  • Emergency access that is permitted, loudly logged, and routed into a review report; plus the process commitment that someone actually reads it
Data at rest and in transit
  • Encryption position, backup encryption, and a tested restore, because an untested backup is a hope
Retention and disposal
  • How long records are kept and what happens to them afterwards, aligned to the facility's own obligations
Third-party access
  • HMO portals, billing vendors, IT contractors, equipment suppliers, each an access path usually forgotten
Breach readiness
  • Who is called, in what order, within what time; a one-page procedure rather than a policy nobody will read at 2am
Remediation plan
  • Findings ranked by exploitability and by clinical impact, each with a fix and an effort estimate
Retest
  • Verification that agreed fixes actually landed

Data model

  • Not a build. Deliverables are documents: access inventory, permission matrix, findings register, remediation plan, breach procedure, retest report.

Invariants

  • Not applicable — this is an assessment engagement. The one structural rule: findings are ranked by exploitability and impact, never listed alphabetically or by tool output order.

Offline behavior

Not applicable.

Hard trade-offs

The difficult decisions, stated plainly — not trimmed for length.

An access review names people, and some of those people will be senior.

The most common real finding in a facility of this kind is that a long-serving administrator has accumulated access far beyond their role, often because they were helpful during a crisis years ago. Removing it is a political act, not a technical one. Afivox reports findings to the engaging authority confidentially and does not adjudicate internal consequences — and the engagement letter should say so before work starts.

Break-glass access only works if someone reviews the report.

The system can generate it; only the facility can commit to reading it. A remediation plan that depends on a review nobody performs should be marked as unmitigated rather than closed.

Regulatory note

[FILL: confirm the facility's specific obligations — NDPA, any HMO contractual requirements, and professional body guidance — before scoping. Afivox assesses against the facility's stated obligations and does not offer legal advice on what they are.]

End state

What would be true about their day once this is running.

  • The facility can say who can see what, and prove who has seen what.
  • Access reflects current roles rather than historical accumulation.
  • Emergency access is possible, logged and reviewed.
  • Backups restore, tested rather than assumed.
  • There is a one-page procedure for the day something goes wrong.

Let's map how your operation actually runs.

One session. We look at what's breaking, and what we'd build around it — whether or not you hire us afterward.

Start the operations review