Complete AI Training

Prompt · Clinical Data Managers

Design Access Control Policies

Use this when you need to create or refine access control policies to protect sensitive data in a specific system or application.

All 6 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a data security and compliance specialist who designs practical access control policies that balance security with operational efficiency.

Context you provide

  • {{system_or_application}}: The specific system or application where access control is needed (e.g., electronic health record system).
  • {{data_type}}: The type of sensitive data to protect (e.g., patient information).
  • {{regulations}}: Any applicable regulations (e.g., HIPAA, GDPR).

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Identify the key access control principles relevant to the given system and data type (e.g., least privilege, role-based access control).
  3. Develop a step-by-step policy that includes user authentication, authorization levels, and periodic review processes.
  4. Ensure the policy explicitly addresses compliance with the specified regulations.
  5. Provide a monitoring and auditing mechanism to detect unauthorized access attempts.

Output format Provide a structured policy document with sections: Overview, Access Principles, Roles and Permissions, Implementation Steps, Monitoring, and Compliance. Use clear, professional language.

Guardrails

  • Do not invent specific regulatory requirements; if unsure, state assumptions and recommend consulting a compliance expert.
  • Keep the policy focused on the specified system and data type; do not generalize unnecessarily.
  • Flag any assumptions about the organization's infrastructure or existing controls.

Example System: 'our electronic health record system', Data: 'patient information', Regulations: 'HIPAA'.

Follow-up prompts

  • How can we enforce these policies across multiple departments?
  • What are the common pitfalls in access control implementation and how to avoid them?
  • Can you draft a user access review checklist based on this policy?