User Roles Matrix <<Initiative Name>>
INSTRUCTIONS:
User permissions template can be used to identify which user groups have access to the system and the PHI it contains as well as identifying some of the key functionality that they have
access to. The below table is an example only, and should be customized according to your initiative. Also, it is important to note that occassionally an individual may assume multiple
roles in an initiative. For example, a physician may also be the privacy officer for a small organization. Therefore, that individual would be assigned both roles in the below scenario.
Role-Based Access Matrix
User Group Purpose for Access Information Objects Consent Management
PHI Reports Consent Management
Demographics Clinical Notes Labs Etc Privacy Admissions Create CD Modify CD Override CD
Receptionists Requires access to basic C,R,U N/A N/A N/A N/A R Y Y N
demographic data to
register patients
Emergency Room Will register and update C,R,U R R R N/A N/A Y Y N
Receptionists patients, but also often
communicates clinical
information to Providers
Emergency Room Provides treatment to R C,R,U C,R,U C,R,U N/A N/A Y Y Y
Healthcare Providers patient
In-patient physicians Provides treatment to R C,R,U C,R,U C,R,U N/A N/A Y Y Y
patient
In-patient nurses Provides treatment to R C,R,U C,R,U C,R,U N/A N/A Y Y N
patient, but does not need
to access masked data
Social Workers Provides treatment to R C,R,U N/A N/A N/A N/A N N N
patient, but does not need
access to lab results, etc
Privacy Officer Only requires access to R N/A N/A N/A C,R N/A Y Y N
privacy management
functions
Database Administrator Has database-level access to R R R R C,R C,R N/A N/A N/A
provide support
Legend:
C Create
R Read
U Update
D Delete
User Roles Matrix.xlsx 1