Access Reviews & Compliance

Complete access reviews in under an hour. Not days.

HIPAA requires regular review of who has access to what. In practice, that means someone manually comparing PointClickCare accounts against HR records — facility by facility, account by account. Credric automates the comparison so you can focus on the decisions, not the data gathering.

app.credric.com
Access review campaign showing drift detection, orphaned accounts, and certification progress

Drift Detection

Automatically compare PointClickCare user accounts against your identity source. Surface accounts where access, roles, or permissions have diverged from what your source of truth says they should be.

Orphan Identification

Find accounts with no matching active employee in your identity source. These are the accounts that survive terminations, transfers, and system migrations — and the ones auditors ask about first.

Bulk Certification

Review flagged accounts and make certification decisions in bulk. Approve continued access, flag for follow-up, or initiate revocation — across all facilities in a single session.

How a review campaign works

1

Start a review campaign

Credric snapshots your current PointClickCare user accounts and compares them against your identity source.

2

Drift and orphans are flagged

Accounts where access has diverged or where no matching employee exists are automatically surfaced.

3

Review and decide

Certify continued access, flag for follow-up, or initiate revocation — individually or in bulk.

4

Revoke and remediate

Flagged accounts can be disabled directly through Credric. Every decision is logged in the audit trail.

5

Complete with audit trail

The full review — every decision, every reviewer, every timestamp — is available for compliance reporting.

Built for HIPAA compliance reviews

Credric's access review capabilities directly support key HIPAA Security Rule requirements.

§164.312(a)(1)

Access Control

Technical safeguards to control who can access ePHI systems.

§164.308(a)(4)

Access Management

Policies for granting and reviewing access to ePHI.

§164.308(a)(1)(ii)(D)

Activity Review

Regular review of audit logs, access reports, and security incidents.

Common questions about access reviews

How often should we run access reviews?

HIPAA requires regular access reviews but doesn't prescribe a specific interval. Most healthcare organizations run quarterly or semi-annual reviews. Credric supports configurable review frequencies so you can match your compliance requirements.

What is access drift?

Access drift occurs when a user's actual PointClickCare access diverges from what your identity source says it should be. This happens when changes are made directly in the system, when sync errors occur, or when manual provisioning bypasses the normal workflow. Credric detects these discrepancies automatically.

What are orphaned accounts?

Orphaned accounts are PointClickCare user accounts that have no matching active employee in your identity source. They typically result from incomplete offboarding, system migrations, or manual account creation that was never linked to an identity source. These are the accounts auditors look for first.

Get Started

Ready to automate
PointClickCare provisioning?

See how Credric can give your IT team back the hours they spend on manual account management — regardless of your infrastructure.

By submitting, you agree to our Privacy Policy. We'll never share your information.