Skip to main content
Security Safeguards

Least Privilege

Granting each user or process only the minimum access needed to do its job.

Least Privilege is a security principle of granting each user, application, or process only the minimum access rights required to perform its function, and nothing more.

It directly supports HIPAA's minimum necessary standard and is commonly implemented through role-based access control. Limiting privileges shrinks the attack surface and reduces the damage a compromised account can do to ePHI. A per-function example is in AWS Lambda HIPAA compliant.

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.