PHI Break-Glass Governance
A health system made emergency PHI access a governed, step-up, fully audited break-glass path, so clinicians could reach restricted records in a crisis without leaving the privacy control plane.
A health system locked sensitive records — behavioral health, VIP patients, employee charts — behind tight access policy. But emergencies do not respect policy boundaries. A clinician treating an unconscious patient sometimes needed a record they were not routinely entitled to see, and the existing answer was a blunt one: a generic “emergency access” account that bypassed controls entirely and left a weak trail.
The system needed break-glass that granted the access when it was genuinely needed, demanded proof and a reason, and produced an audit record strong enough to review every single use.
The challenge
Break-glass sits on a knife edge. Make it too hard and clinicians route around it in a crisis; make it too easy and it becomes a standing backdoor into the most sensitive PHI in the building. The legacy shared emergency account failed both ways: it was over-broad, unattributed, and reviewed by nobody. Privacy officers could not tell a justified emergency from a curiosity peek after the fact.
They wanted emergency access bound to the individual clinician, gated by a step-up and a stated reason, time-boxed, and flagged for mandatory review.
What Veripass deployed
Veripass modeled break-glass as a governed, policy-defined elevation rather than a separate account. When a clinician hit a record outside their normal access profile, context-aware policy offered a break-glass path instead of a flat denial. Invoking it required the clinician to step up with adaptive MFA over phone TOTP and record a reason; only then did policy grant a time-boxed elevation scoped to that record.
The elevation was attributed to the real clinician’s identity, never a shared account, and the entire sequence — the denial, the step-up, the stated reason, the records touched, and the automatic expiry — was written to the immutable audit trail and flagged for privacy review.
- Break-glass modeled as a governed policy elevation, not a shared account
- Context-aware policy offering emergency access in place of flat denial
- Mandatory step-up via adaptive MFA over phone TOTP plus a recorded reason
- Time-boxed elevation scoped to the specific record
- Elevation attributed to the individual clinician’s identity
- Immutable audit trail capturing denial, reason, access, and expiry, flagged for review
Because every break-glass event carried the clinician’s identity, the reason they gave, and the exact records they reached, privacy officers got a focused review queue instead of an opaque shared-account log. The access expired on its own, so emergency entitlements never silently became permanent.
Outcome
Clinicians kept a fast, real path to records in a genuine emergency — the control did not get in the way of patient care — while the generic backdoor account was retired. Every emergency access now named a person, carried a reason, and expired on schedule.
Privacy officers moved from forensic guesswork to a clean review queue: each break-glass use was attributable, justified, and reconstructable from one immutable trail, turning emergency PHI access from a compliance liability into a governed, defensible exception.
More deployments
Boutique Clienteling Access
A luxury retailer secured its clienteling app so associates reach client books and purchase history only within their boutique and role, with step-up verification before any high-net-worth profile opens.
Contractor QR Visitor Passes
A campus operator issued time-boxed QR visitor passes bound to a verified contractor identity, so on-site access was scoped, auto-expiring, and revocable from a single control plane.
Fintech Open-Banking APIs
A fintech secured its open-banking API surface with Veripass API keys for machine-to-machine access and scoped, capability-based authorization, so every partner integration ran on least privilege.


