Use emergency access only for clearly defined clinical exceptions, keep it narrowly scoped, and review every use after the event. Break-glass should remain auditable, rare and time-bounded in practice, even when the patient situation is urgent. If emergency access becomes routine, it is no longer an exception and the identity model is weakened.
What governance means for break-glass ePA access
Governance for break-glass ePA access starts with treating it as an exception path, not a parallel operating model. The control objective is to preserve continuity in urgent care while preventing emergency access from becoming the default workaround for poor role design, weak delegation, or delayed provisioning. That means the organisation defines when it may be used, who may approve or invoke it, and what evidence must exist afterward.
A useful governance model separates the clinical reason for access from the technical mechanism that grants it. In practice, that means a documented emergency trigger, a tightly bounded access scope, and a record of the rationale, time, patient context, and user involved. The stronger the predefinition, the easier it is to distinguish a legitimate clinical exception from convenience-driven use.
Because break-glass changes the normal access model, it should be reviewed as both an access-control issue and a patient-safety issue. If the exception path is too broad, staff may rely on it instead of correcting underlying workflow or permission defects. If it is too narrow or too slow, clinicians may be blocked during time-critical care. Good governance is the balance between those failure modes.
How to keep emergency access auditable and time-bounded
Auditable break-glass access needs clear attribution, timestamped event logging, and a reliable post-event review process. The access record should show who used it, what was accessed, how long the elevated access remained active, and whether the use was later justified. Without those elements, the organisation can neither reconstruct the clinical decision nor detect misuse patterns.
Time-bounding matters because emergency access is meant to expire as soon as the urgent need ends. A short-lived elevation window reduces the chance that a genuine emergency becomes persistent excess privilege. Where possible, the workflow should require step-up review or explicit closure after the incident, rather than leaving the elevated state to drift until someone remembers to remove it.
Break-glass should also be monitored against volume and pattern. Repeated use by the same role, ward, shift, or service line is often a signal that the underlying access model is misaligned with operational reality. In those cases, governance should focus on why the exception is needed so often, not only on whether each individual use was authorised.
What good practice looks like in healthcare operations
Good practice is to make break-glass available only for clearly defined clinical exceptions, then review every use after the event to decide whether the access was justified, whether the record was complete, and whether the event reveals a process defect. That review should feed back into policy, training, and access design so the exception path becomes less necessary over time.
For healthcare organisations, the practical test is whether the emergency pathway remains rare under normal operations. If staff can reach for it routinely, the organisation has usually shifted a governance problem into an access-control problem. At that point, the right response is often to tighten standard access, improve coverage for on-call scenarios, and simplify legitimate delegated access rather than normalise break-glass.
Break-glass governance also benefits from clear ownership. Clinical leadership, privacy or compliance functions, and identity or access administrators each see different failure modes, so the review process should assign one accountable owner for exception policy, one for technical logging, and one for post-use follow-up. That separation prevents a critical control from becoming “everybody’s job” and therefore nobody’s.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Break-glass governance depends on tightly scoped account use and review. |
| AU-2 — Event Logging | Auditable emergency access requires complete event records for every invocation. | |
| AC-6 — Least Privilege | Emergency access should stay narrowly scoped and time-bounded to reduce excess privilege. | |
| Recommendation — Define and review emergency account access so elevated use remains exceptional. Log each break-glass event with user, scope, time, and reviewer evidence. Limit break-glass access to the minimum scope and duration needed. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Healthcare break-glass governance is an access-control exception that needs policy and enforcement. |
| A.8.2 — Privileged access rights | Break-glass is privileged access and must be controlled, reviewed, and justified. | |
| Recommendation — Document and enforce exception-based access rules for emergency ePA use. Restrict and review emergency privileged access rights on a defined schedule. | ||
Practitioner Guidance
What to prioritise: Define the emergency trigger and the approval path before tuning the technology. If clinicians are invoking break-glass to work around ordinary access delays, fix the standard access model first.
What to verify: Confirm that each event leaves a complete trail, including user identity, timestamp, patient or record scope, duration, and reviewer sign-off. If any of those elements cannot be produced reliably, the control is too weak to trust.
Common mistake: Treating “break-glass enabled” as success. The real measure is whether emergency access stays exceptional, bounded, and explainable after the fact.
Practitioner takeaway: The best break-glass design is one that clinicians can use in a true emergency but are unlikely to need in routine care; high usage is usually a governance defect, not a success metric.