EHRS-FM IG

ISO/HL7 10781 - Electronic Health Record System Functional Model, Release 2.1
0.16.0 - CI Build

Publish Box goes here

Requirements: TI.2.1.2.8 Extraordinary User Access (Break the Glass) Security Audit Trigger (Function)

Active as of 2024-08-12
Statement N:

Manage Audit Trigger initiated to track extraordinary user access (break the glass).

Description I:

Capture extraordinary user access (break the glass), both routine and exceptional, including key metadata (who, what, when, where, why).

Criteria N:
TI.2.1.2.8#01 SHALL

The system SHALL audit each occurrence when extraordinary access is successful (e.g., "break the glass" scenario).

TI.2.1.2.8#02 SHALL

The system SHALL capture identity of the organization.

TI.2.1.2.8#03 conditional SHALL

IF known, THEN the system SHALL capture identity of the user.

TI.2.1.2.8#04 SHALL

The system SHALL capture identity of the system.

TI.2.1.2.8#05 SHALL

The system SHALL capture the event initiating audit trigger.

TI.2.1.2.8#06 SHALL

The system SHALL capture the date and time of the event initiating audit trigger.

TI.2.1.2.8#07 SHALL

The system SHALL capture identity of the location (i.e., network address).

TI.2.1.2.8#08 SHALL

The system SHALL capture the rationale for extraordinary user access.