February 2, 2026 · Ken Armstrong
45 CFR 164.308(a)(3)(ii)(C) covers termination procedures. In most assessments the control itself is present and the record proving it is not, which is why this requirement produces findings at organizations that are, in practice, doing the work.
Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(B) of this section.
That is the operative language of 45 CFR 164.308(a)(3)(ii)(C). Read it closely: it describes an outcome to achieve, not a product to buy, which is why two practices of the same size can satisfy it in different ways and both be right.
This is an addressable implementation specification, and addressable does not mean optional. Under 45 CFR 164.306(d)(3) you assess whether the specification is reasonable and appropriate in your environment, and then either implement it, or implement an equivalent alternative and document why. The documented reasoning is itself part of the requirement, so an undocumented decision to skip it is the finding.
In an assessment, 45 CFR 164.308(a)(3)(ii)(C) is not one question. It resolves into several, and each one is really asking for a different artifact:
Ownership usually sits with the security official, though the evidence is often produced by someone else, which is where the trail breaks. A control that works but has no owner tends to stop working the month the person who quietly maintained it changes roles.
Every covered entity and every business associate, at any size. 45 CFR 164.306(b) allows flexibility of approach, so a two-provider practice and a hospital system may implement this differently and both comply. What flexibility does not allow is skipping the decision: the smaller the organization, the more the written reasoning carries the weight, because there is no scale of operation to make the control self-evident.
The sequence below is the order that produces evidence as a by-product rather than as a separate documentation exercise:
The same evidence answers more than one framework. The questions behind 45 CFR 164.308(a)(3)(ii)(C) also map to NIST CSF GV.RR-04, PR.AA-05; ISO 27001 A.5.11, A.5.18, A.6.5; SOC 2 CC6.2, CC6.3; NIST 800-53 AC-2, PS-4, PS-5; CIS v8 5.3, 6.2; HITRUST 02.g. That matters for scoping: if you are working toward SOC 2 or an ISO certification alongside HIPAA, this control is one piece of work and several answers, provided the artifact is written once and referenced rather than rewritten per framework.
For this requirement the artifact types that satisfy it are procedure and record. The distinction matters more than it looks: a policy states what you intend to do, a procedure states how, and a record proves it happened on a date. Auditors ask for all three, and a practice that has written the first two often has nothing for the third.
Date every artifact and keep the superseded versions. 45 CFR 164.316(b)(2)(i) requires documentation be retained for six years from the date of its creation or the date when it last was in effect, whichever is later, so a policy you replaced two years ago is still part of the record.
The most common failure here is treating addressable as optional. A practice decides the specification does not fit, implements nothing, and writes nothing down. At assessment the answer to "why not" is a verbal explanation, which is not evidence. The second most common failure is the opposite: implementing an alternative that works, and still not recording the reasoning, so the control looks accidental.
If 45 CFR 164.308(a)(3)(ii)(C) is new to you, the useful first step is not a policy template. It is writing down what you already do, dating it, and naming an owner. That turns an undocumented practice into evidence, and it usually reveals the real gap.