Back to case studies // authorization

PHI Break-Glass Governance

A health system made emergency PHI access a governed, step-up, fully audited break-glass path, so clinicians could reach restricted records in a crisis without leaving the privacy control plane.

March 24, 2025 · Veripass
PHI Break-Glass Governance

A health system locked sensitive records — behavioral health, VIP patients, employee charts — behind tight access policy. But emergencies do not respect policy boundaries. A clinician treating an unconscious patient sometimes needed a record they were not routinely entitled to see, and the existing answer was a blunt one: a generic “emergency access” account that bypassed controls entirely and left a weak trail.

The system needed break-glass that granted the access when it was genuinely needed, demanded proof and a reason, and produced an audit record strong enough to review every single use.

The challenge

Break-glass sits on a knife edge. Make it too hard and clinicians route around it in a crisis; make it too easy and it becomes a standing backdoor into the most sensitive PHI in the building. The legacy shared emergency account failed both ways: it was over-broad, unattributed, and reviewed by nobody. Privacy officers could not tell a justified emergency from a curiosity peek after the fact.

They wanted emergency access bound to the individual clinician, gated by a step-up and a stated reason, time-boxed, and flagged for mandatory review.

What Veripass deployed

Veripass modeled break-glass as a governed, policy-defined elevation rather than a separate account. When a clinician hit a record outside their normal access profile, context-aware policy offered a break-glass path instead of a flat denial. Invoking it required the clinician to step up with adaptive MFA over phone TOTP and record a reason; only then did policy grant a time-boxed elevation scoped to that record.

The elevation was attributed to the real clinician’s identity, never a shared account, and the entire sequence — the denial, the step-up, the stated reason, the records touched, and the automatic expiry — was written to the immutable audit trail and flagged for privacy review.

  • Break-glass modeled as a governed policy elevation, not a shared account
  • Context-aware policy offering emergency access in place of flat denial
  • Mandatory step-up via adaptive MFA over phone TOTP plus a recorded reason
  • Time-boxed elevation scoped to the specific record
  • Elevation attributed to the individual clinician’s identity
  • Immutable audit trail capturing denial, reason, access, and expiry, flagged for review

Because every break-glass event carried the clinician’s identity, the reason they gave, and the exact records they reached, privacy officers got a focused review queue instead of an opaque shared-account log. The access expired on its own, so emergency entitlements never silently became permanent.

Outcome

Clinicians kept a fast, real path to records in a genuine emergency — the control did not get in the way of patient care — while the generic backdoor account was retired. Every emergency access now named a person, carried a reason, and expired on schedule.

Privacy officers moved from forensic guesswork to a clean review queue: each break-glass use was attributable, justified, and reconstructable from one immutable trail, turning emergency PHI access from a compliance liability into a governed, defensible exception.

More deployments

Boutique Clienteling Access

Boutique Clienteling Access

A luxury retailer secured its clienteling app so associates reach client books and purchase history only within their boutique and role, with step-up verification before any high-net-worth profile opens.

Contractor QR Visitor Passes

Contractor QR Visitor Passes

A campus operator issued time-boxed QR visitor passes bound to a verified contractor identity, so on-site access was scoped, auto-expiring, and revocable from a single control plane.

Fintech Open-Banking APIs

Fintech Open-Banking APIs

A fintech secured its open-banking API surface with Veripass API keys for machine-to-machine access and scoped, capability-based authorization, so every partner integration ran on least privilege.