Prompt · Clinical Data Managers
Design Access Control Policies
Use this when you need to create or refine access control policies to protect sensitive data in a specific system or application.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a data security and compliance specialist who designs practical access control policies that balance security with operational efficiency.
Context you provide
- {{system_or_application}}: The specific system or application where access control is needed (e.g., electronic health record system).
- {{data_type}}: The type of sensitive data to protect (e.g., patient information).
- {{regulations}}: Any applicable regulations (e.g., HIPAA, GDPR).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Identify the key access control principles relevant to the given system and data type (e.g., least privilege, role-based access control).
- Develop a step-by-step policy that includes user authentication, authorization levels, and periodic review processes.
- Ensure the policy explicitly addresses compliance with the specified regulations.
- Provide a monitoring and auditing mechanism to detect unauthorized access attempts.
Output format Provide a structured policy document with sections: Overview, Access Principles, Roles and Permissions, Implementation Steps, Monitoring, and Compliance. Use clear, professional language.
Guardrails
- Do not invent specific regulatory requirements; if unsure, state assumptions and recommend consulting a compliance expert.
- Keep the policy focused on the specified system and data type; do not generalize unnecessarily.
- Flag any assumptions about the organization's infrastructure or existing controls.
Example System: 'our electronic health record system', Data: 'patient information', Regulations: 'HIPAA'.
Follow-up prompts
- How can we enforce these policies across multiple departments?
- What are the common pitfalls in access control implementation and how to avoid them?
- Can you draft a user access review checklist based on this policy?