The organisation should establish and maintain an authorisation register to document all granted access rights. For each authorisation, the register should record the user, the granted rights, the person who approved the access, and the date of granting. This register serves as a central point for auditing and managing access control.
For each authorisation, the register should clarify the purpose of the access and the associated role. The register should log when authorisation has been granted and when it has been revoked. It should identify the user's organisation and specify if they have authorisation to access health information in external organisations. Self-authorisaton should be justified if it is allowed.