SpecsModelExplore
Overview
Actors
ClinicianPatientResearcherCompliance Officer
External Systems
Clinical Data Product
Compliance Officer
Goals
Where they work
SpecsModelExplore
Compliance Officer
OverviewGuideLinks and Communications

Compliance Officer

The Compliance Officer reviews access patterns, attests periodic access reviews and verifies that consent records match what patients signed.

Accountability over convenience

Every PHI read and write should be reconstructable from the audit trail. Their job is to catch the access that shouldn’t have happened — not to block care.

Goals

  • Search audit logs for suspicious access patterns.
  • Review flagged chart opens outside care relationships.

Where they work

Governance & Audit

Consent, audit logs and access reviews.

Audit Service

Search audit history and investigate alerts.

Access Review

Quarterly attestation campaigns.