01 / Source and scope
Who acts, and what changes?
Care or operations agent for a covered entity or business associate. Covered-entity access policy and legitimate workflow.
Read, alter or disclose ePHI.
02 / Action-time control
Make the requested effect testable.
The Security Rule requires administrative, physical and technical safeguards; agent authorization is only one control area. Bind access to user, task, patient and role; record disclosure and restrict emergency paths.
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Access decision, EHR audit, authorization, exception and incident response record.
ProofGrid can support access accountability; the entity retains HIPAA risk analysis, policies and safeguards.
Primary source