Forum

Notifications
Clear all

What is the best practice for agent access reviews? Quarterly? Per-patient?

2 Posts
2 Users
0 Reactions
25 Views
(@kernel_sec_taro)
Active Member
Joined: 3 months ago
Posts: 14
Topic starter   [#1286]

Agent access reviews at "quarterly" are useless for HIPAA. You're reviewing logs, not policy. The trigger must be per-patient-access or per-unusual-behavior.

Minimum necessary means the agent's context window and tool scope must be constrained per session. You need a technical enforcement layer, not a policy doc.

* Access reviews should be automated against audit logs.
* Trigger on: first access to a patient record, access outside normal hours, abnormal data volume pulled.
* Map agent actions to a specific user's session ID. No shared service accounts.

Example log filter for a potential review trigger (eBPF/auditd):
```
type=SYSCALL msg=audit(...) pid= exe="/opt/agent/binary" key="phi_access" records_accessed=150 patient_id=
```
If `records_accessed` > threshold for a single patient in a session, flag for immediate review.

The "review" is a human verifying the agent's retrieved context was justified for that specific task. Anything else is theater.

--taro


--taro


   
Quote
(@agent_log_watcher)
Eminent Member
Joined: 3 months ago
Posts: 19
 

> Trigger on: first access to a patient record, access outside normal hours, abnormal data volume pulled.

This is the correct starting point, but the implementation details for these triggers are critical. Your eBPF example is a good syscall-layer capture, but you also need structured application logs from the agent itself to understand the *intent* behind the access. A syscall shows a file read of 150 records, but an application log should capture the user's natural language query that prompted it.

Without that correlation, your review is just guessing. The log schema must fuse the user session, the agent's reasoning (e.g., the query or task label), and the resultant data access. Otherwise, you'll flag every bulk export for a surgical prep as anomalous.

Also, "outside normal hours" requires a dynamic baseline per role - a hospitalist's 3 a.m. access might be normal, but a billing agent's isn't.


Log everything, trust nothing.


   
ReplyQuote