Skip to main content
Category: Physical and Technical Safeguards

Emergency Access Procedure

Also known as: Break Glass Access, Break Glass Procedure, Emergency Access Process
Simply put

An Emergency Access Procedure is a documented method that lets authorized staff reach electronic protected health information (ePHI) during an emergency, such as a life-threatening patient care situation, when normal access controls might otherwise get in the way. It is designed to provide this access in a controlled way that does not weaken an organization's routine security protections. A common example is 'break glass' access, where pre-staged emergency accounts can be activated quickly when time is critical.

Formal definition

Under the HIPAA Security Rule, an Emergency Access Procedure is a technical safeguard implementation specification associated with access controls, requiring covered entities and business associates to establish and implement procedures for obtaining necessary ePHI during an emergency. Within the Security Rule framework this is generally treated as a required implementation specification rather than an addressable one, meaning the covered entity must implement it, though the specific mechanism is left to the organization's discretion based on its risk analysis. Common implementations include 'break glass' access based on pre-staged emergency user accounts that can be activated with reasonable administrative overhead, paired with logging, monitoring, and after-the-fact review to preserve accountability. Readers should confirm the current regulatory text and CFR citation, as the precise wording and status of this implementation specification should be verified against the applicable version of the Security Rule; note also that this procedure applies to ePHI only and does not itself address emergency access to paper or oral PHI governed by the Privacy Rule.

Why it matters

Emergency Access Procedures address a fundamental tension in healthcare security: the same access controls that protect electronic protected health information (ePHI) from unauthorized use can, in a genuine emergency, delay a clinician who needs patient data immediately. When a patient's life may be at stake, the inability to reach records quickly can carry real consequences. An Emergency Access Procedure resolves this tension by providing a controlled, pre-planned way to obtain necessary ePHI during an emergency without dismantling the organization's routine security posture.

Under the HIPAA Security Rule, this procedure is generally treated as a required implementation specification within the access control safeguards, meaning covered entities and business associates are expected to establish it rather than treat it as optional. The specific mechanism, however, is left to the organization's discretion based on its risk analysis. This flexibility is important, but it also means organizations bear responsibility for designing a procedure that genuinely balances rapid access against accountability. A 'break glass' approach that grants access with no logging or after-the-fact review can undermine the very protections the Security Rule is meant to preserve.

Because this safeguard applies only to ePHI, it does not by itself address emergency access to paper or oral PHI, which falls under the broader HIPAA Privacy Rule. Organizations should also confirm the current regulatory text and CFR citation, as the precise wording and status of this implementation specification should be verified against the applicable version of the Security Rule, and state law or other frameworks may impose additional requirements.

Who it's relevant to

Security Officers and IT Administrators
Those responsible for configuring access controls must design, implement, and maintain the emergency access mechanism, including any pre-staged 'break glass' accounts and the logging and monitoring needed to preserve accountability. They should ensure the procedure is grounded in the organization's risk analysis and that the specific mechanism chosen balances rapid access against security.
Clinical and Front-Line Staff
Authorized personnel who may need to invoke emergency access during patient care situations must understand when and how to use the procedure. Because emergency access is a controlled override rather than a routine method, staff should be trained on the circumstances that justify its use and the fact that its use is generally logged and subject to review.
Compliance and Privacy Officers
These professionals should confirm that the organization has an Emergency Access Procedure in place, given its status as a generally required implementation specification, and that after-the-fact review processes are functioning. They should also recognize that this safeguard covers ePHI only and does not address emergency access to paper or oral PHI under the Privacy Rule, and should verify obligations against the current regulatory text.
Business Associates and Subcontractors
Business associates and their subcontractors that create, receive, maintain, or transmit ePHI on behalf of covered entities are also generally expected to implement Emergency Access Procedures for the systems they manage. The specific obligations typically flow through business associate agreements and should be confirmed against the applicable Security Rule requirements.

Inside Emergency Access Procedure

Regulatory Placement
Emergency Access Procedure is a required implementation specification under the Access Control standard within the technical safeguards of the HIPAA Security Rule. Because it is a required (not addressable) specification, covered entities and business associates that maintain ePHI must generally implement it.
Scope: ePHI Only
As part of the Security Rule, this procedure applies specifically to electronic protected health information (ePHI). It does not extend to PHI in oral or paper form, which fall under the Privacy Rule.
Purpose
The procedure establishes a documented method for obtaining necessary access to ePHI during an emergency or other situation where normal access controls may be unavailable or insufficient, so that patient care and critical operations can continue.
Documented Access Method
It typically includes predefined steps or mechanisms (sometimes called 'break-glass' access) that authorized workforce members can use to reach ePHI when standard authentication or authorization paths are disrupted, such as during a system outage or crisis.
Relationship to Other Access Controls
It works alongside the other Access Control implementation specifications, including unique user identification (required), automatic logoff (addressable), and encryption/decryption (addressable). Emergency access is intended to supplement, not replace, routine access safeguards.

Common questions

Answers to the questions practitioners most commonly ask about Emergency Access Procedure.

Is an emergency access procedure optional because it is an addressable implementation specification?
No. Emergency access procedure is a required implementation specification under the Security Rule's access control standard, not an addressable one. Even setting that aside, addressable does not mean optional in general; it means a covered entity or business associate must assess whether the specification is reasonable and appropriate, and if not, implement a documented equivalent alternative or record why it is not applicable. In the case of emergency access, the specification must be implemented to establish procedures for obtaining necessary ePHI during an emergency. Readers should confirm the current regulatory text for the specific classification.
Does having an emergency access procedure mean normal access controls and audit requirements can be bypassed during any urgent situation?
No. An emergency access procedure is intended to allow authorized access to necessary ePHI during a genuine emergency, such as a system failure or a clinical situation where normal access is unavailable. It is not a general exception that suspends other Security Rule safeguards. Access during emergencies should generally still be subject to accountability measures such as audit controls, and the procedure should define who may invoke it and under what conditions. It is a controlled mechanism, not an open-ended override.
Who should be authorized to invoke an emergency access procedure, and how is that typically determined?
The individuals authorized to invoke emergency access are generally defined by the organization based on its own risk analysis, workforce roles, and operational needs. Many organizations limit this to specific roles that plausibly require access to ePHI in a crisis, such as certain clinical or IT personnel. HIPAA does not prescribe a specific list of roles, so organizations should document their authorization criteria in policy. State law or organizational accreditation requirements may impose additional expectations that should be verified separately.
How should emergency access events be logged and reviewed after they occur?
As a practical matter, organizations commonly configure systems so that emergency access invocations are recorded and flagged for later review, often through audit controls implemented under the Security Rule's separate audit control standard. Post-event review typically helps confirm that access was appropriate and that no misuse occurred. The specific logging mechanisms and review cadence are left to the organization to determine based on its risk analysis; HIPAA does not dictate a single technical approach.
How does an emergency access procedure relate to break-the-glass functionality in electronic health record systems?
Break-the-glass features in many EHR and health information systems are one common technical mechanism organizations use to satisfy the emergency access procedure requirement. Such features generally allow an authorized user to override normal access restrictions in an emergency while creating a record of the override. However, break-the-glass is a vendor or system feature rather than a regulatory term, and implementing it does not by itself demonstrate compliance. The overall procedure, including policy, authorization, and review, is what addresses the requirement.
How often should an emergency access procedure be tested or reviewed?
HIPAA does not specify a fixed testing or review frequency for emergency access procedures. In most cases, organizations incorporate review of this procedure into their broader periodic evaluation and risk analysis processes, updating it when systems, workforce roles, or operational conditions change. Periodic testing can help confirm that the procedure works as intended during an actual emergency. Organizations should document their review approach and verify any additional expectations under applicable frameworks or the current HITRUST CSF version if they pursue certification.

Common misconceptions

An Emergency Access Procedure is optional because organizations can rely on their normal access controls.
Under the Security Rule, the Emergency Access Procedure is a required implementation specification, not an addressable one. Covered entities and business associates handling ePHI are generally expected to implement it rather than treating it as discretionary.
Emergency access means bypassing all security and accountability controls when a crisis occurs.
Emergency access is meant to provide a controlled, documented pathway to needed ePHI during emergencies, not to eliminate accountability. Access still typically needs to be traceable and consistent with the organization's broader safeguards; the specific mechanics should be verified against the current regulatory text and organizational policy.
This procedure protects all forms of protected health information.
Because it lives within the Security Rule, the Emergency Access Procedure addresses only electronic PHI. Emergency access to paper or oral PHI would be governed by Privacy Rule considerations rather than this technical safeguard.

Best practices

Formally document the Emergency Access Procedure in writing, describing who may invoke it, under what conditions, and the specific steps involved, since it is a required implementation specification.
Define and limit which workforce members are authorized to use emergency ('break-glass') access, aligning access to legitimate care and operational needs.
Integrate the procedure with your other Access Control specifications, such as unique user identification, so that emergency access remains attributable to an individual wherever feasible.
Establish logging and after-the-fact review of emergency access events to support accountability and detect potential misuse.
Test the procedure periodically against realistic scenarios such as system outages to confirm it actually provides needed access when normal controls fail.
Review and update the procedure as systems and workflows change, and confirm current requirements against the applicable Security Rule text and any additional obligations under state law or the HITECH Act.