Routine consent-based access only allows records to be shared under the patient’s normal authorisation rules. Break the glass access is an emergency override used when a patient cannot provide consent and care would otherwise be delayed. The override should be limited, recorded, and auditable so privacy is preserved while clinicians retain access in critical situations.
How the Two Access Modes Differ in Practice
Routine consent-based access is the normal operating mode, where the record is shared only when the patient’s authorisation rules allow it. Break the glass is a controlled exception: clinicians can override the usual consent gate in an emergency, but the system should make that exceptional use obvious, bounded, and reviewable so it does not become a general shortcut.
The practical difference is not just permission, it is governance. Routine access assumes the patient’s preferences and the organisation’s access rules are both available and enforceable. Break the glass assumes those rules may need to be bypassed temporarily to prevent harm, so the question becomes how to permit access without losing accountability or creating permanent overexposure.
That distinction matters because emergency access changes the trust model. Identity Data Privacy and Consent Guide is a useful companion here because the core issue is still lawful, purpose-limited access to sensitive health data, even when the clinical situation forces an override.
Why Break the Glass Exists in Electronic Medical Records
Break the glass exists for situations where waiting for normal consent handling could delay care. In an emergency, clinicians may need immediate access to allergies, medications, diagnoses, imaging, or recent notes when the patient cannot consent or the normal workflow is unavailable. The override is therefore a patient-safety control, not a convenience feature.
Because it bypasses the ordinary access path, it should be designed as a narrow exception with clear prompts, escalation logic, and post-access review. A well-designed override usually requires justification at the point of use, logs the event, and makes the access visible to compliance or privacy teams after the fact. Break-Glass and Emergency Access Account Guide covers the same operating principle from an access-control perspective: emergency access must be exceptional, protected, and auditable.
In practice, the safest implementations treat break the glass as a temporary exception to normal consent and privilege rules, not as a second, standing access role. That keeps the system aligned with least privilege while still allowing urgent treatment to proceed.
What Good Governance Looks Like Around Emergency Override
Normal consent-based access should map cleanly to the patient’s ongoing authorisation status, with access decisions enforced automatically wherever possible. Break the glass should be a separate path with tighter logging, stronger review, and a clear business rule for when it may be used. If the same workflow is used for both, the emergency override loses its meaning.
Healthcare teams should also distinguish between “can view” and “should view.” The override may open the record, but the clinical user still needs a defensible reason to use it and a defined process for documenting that reason. Privileged Access Management Guide is relevant because break-the-glass access has the same core control requirements as other privileged actions: short duration, strong auditability, and limited standing exposure.
For broader access design, Authorisation Models Guide helps frame the underlying decision: routine access should be policy-driven, while emergency access is an exception state that must be constrained by additional rules rather than widened by default.
Risk and Threat Considerations
Break the glass is valuable precisely because it weakens the usual consent barrier, which makes it a target for misuse if it is poorly governed. The main risk is not the existence of the override, but uncontrolled emergency access, where staff rely on it too often, justification becomes superficial, or logs are not reviewed. In a healthcare record system, that can expose highly sensitive data beyond the intended emergency context.
Failure mechanism: Overbroad trigger conditions, weak justification checks, or inadequate logging let emergency access become routine access by another name. If monitoring is poor, inappropriate access may only be discovered after the fact, when the privacy impact is already done.
Impact: Patients can lose confidentiality, organisations can breach privacy obligations, and clinicians can create avoidable trust and compliance problems even when the original emergency access was clinically defensible.
That is why EU General Data Protection Regulation (GDPR) is relevant as a control lens for this topic, especially where emergency access involves special category health data and records of who accessed what, when, and why.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | EMR users must be authenticated before routine or override access decisions. |
| AC-2 — Account Management | Routine and emergency access both depend on governed accounts and revocation. | |
| AU-2 — Event Logging | Break-the-glass access needs audit events to preserve accountability. | |
| Recommendation — Require strong user authentication before any record access is granted. Manage clinician accounts, roles, and revocation so access stays current. Log emergency access events with user, time, patient, and justification details. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The topic is fundamentally about controlled access versus emergency override. |
| A.5.34 — Privacy and protection of PII | EMR access touches sensitive health data and privacy handling. | |
| Recommendation — Define and enforce access-control rules that separate normal and emergency use. Protect patient data by limiting and reviewing emergency disclosures. | ||
| OWASP ASVS | V8 — Authorization | The distinction is between normal authorisation and exceptional override. |
| V16 — Security Logging and Error Handling | Emergency access must be logged and reviewable after use. | |
| Recommendation — Implement explicit authorization checks for routine access and emergency exceptions. Record and retain break-the-glass events for audit and investigation. | ||
Practitioner Guidance
What to verify: Confirm that routine access and emergency override are technically separate paths, with different logging, review, and justification requirements. If break the glass does not create a distinct audit trail, the control is too weak to trust.
Decision rule: If a clinician can use the override without a documented emergency reason, the implementation is drifting from exception handling into convenience access. Tighten the trigger, then test whether the record still supports urgent care without normal consent delays.
What good looks like: Routine access follows the patient’s standing consent rules, break the glass is rare and reviewable, and privacy or compliance staff can reconstruct every override event quickly from the log evidence.
Practitioner takeaway: The key design goal is not to eliminate emergency access, but to make sure the system can prove that emergency access remained exceptional, justified, and accountable.
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between protecting applications and protecting access?
- What is the difference between break glass access and normal privileged access?