Skip to main content
Security Safeguards

Least Privilege

Also known as: Principle of least privilege, PoLP

Granting each user or process only the minimum access needed to do its job.

Least Privilege is a security principle of granting each user, application, or process only the minimum access rights required to perform its function, and nothing more.

It directly supports HIPAA's minimum necessary standard and is commonly implemented through role-based access control. Limiting privileges shrinks the attack surface and reduces the damage a compromised account can do to ePHI. A per-function example is in AWS Lambda HIPAA compliant.

Share this definition with your team

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.