โ† Identity Fabric
Lab Identity Governance Fabric ยท reference

Healthcare Identity Governance โ€” Epic EMR Acute Facility

who owns what across the identity lifecycle in an acute-care hospital running Epic โ€” a reference RACI and swimlane that the lab fabric maps onto one-to-one
The load-bearing idea

In healthcare, providers aren't hired โ€” they're credentialed. The Medical Staff Office is a second authoritative source alongside HR, and Epic role/template assignment is its own governed step. So the ownership map has more lanes than a typical enterprise โ€” but it is exactly the shape the lab's HRIS โ†’ IGA โ†’ ITSM โ†’ PACS + Duo fabric already governs. This page is the customer-facing reference a technical leader brings to a healthcare Duo engagement.

The provider lifecycle โ€” ownership swimlane

Joiner is credential-driven; leaver inverts to disable-first, notify-after, with a single signed SSF/CAEP event pulling logical and physical access together.

sequenceDiagram
  participant HR as HR / Workforce
  participant MSO as Medical Staff Office
  participant IAM as IAM / Identity
  participant EPIC as Epic Security
  participant DUO as Duo ยท MFA / SSO
  participant IGA as IGA / Governance
  participant PACS as Physical Access
  Note over HR,MSO: JOINER โ€” credential-driven
  MSO->>MSO: credential + privilege โ†’ SER record
  HR->>IAM: staff worker record
  MSO->>IAM: provider identity
  IAM->>DUO: enroll MFA + tap-and-go
  IAM->>EPIC: request Epic template
  EPIC->>EPIC: assign role / subtemplate
  IAM->>PACS: badge to assigned units
  IGA->>IGA: baseline access cert + SoD
  Note over HR,PACS: LEAVER โ€” disable-first, notify-after
  MSO->>IGA: privilege end / termination
  IGA->>IAM: disable identity
  IGA->>DUO: session-revoked (SSF / CAEP)
  DUO-->>EPIC: kill EHR session
  DUO-->>PACS: revoke badge
  

Who owns what โ€” identity RACI

Nine lifecycle activities across the seven owners in an Epic acute facility. Clinicians invoke break-glass and the data/application owner approves access requests โ€” both fold into Consulted below.

ActivityHRMed StaffIAMEpic SecIGASOC/ITDRCompliance/HIM
Onboard staff (nurse / tech)Aโ€”RCIโ€”I
Credential + onboard providerCARCIโ€”C
Epic role / template assignmentโ€”CCACโ€”C
Access request (add'l system)โ€”CRCAโ€”I
Mover (unit / role / locum)ACRCCโ€”I
Leaver + real-time revokeCCARRCI
Break-glass emergency accessโ€”CIRIRA
Access certification / recertICCCAโ€”C
HIPAA access audit / ITDRโ€”โ€”ICCRA
R Responsible โ€” does the work A Accountable โ€” owns the outcome C Consulted โ€” two-way input I Informed โ€” one-way notice

How it maps to the fabric

Every owner lane above is a component the lab already runs โ€” the rehearsal is the customer's org chart in miniature.

HR / Workforce โ†’ HRIS-Lite (Workday-style SoR ยท JML authority)
Medical Staff Office โ†’ IGA-Lite (credentialing as a second source)
IAM / Identity โ†’ AD / Entra / Duo (provisioning ยท MFA ยท tap-and-go)
Epic Security โ†’ application owner, governed via ITSM-Lite change gate
IGA / Governance โ†’ IGA-Lite (recert ยท SoD ยท access review)
SOC / ITDR โ†’ SSF/CAEP + CII risk feed (real-time revoke)
Compliance / HIM โ†’ ITSM-Lite hash-chain audit + access review
Physical Access โ†’ PACS-Lite (SCIM badge ยท SSF revoke)
The "so what" for a Duo customer

The point isn't a new product โ€” it's that this ownership map already exists in the customer's org. The fabric just makes each lane a governed, auditable step on the identity they already run: Duo as the decision point, the same joiner/mover/leaver, extended to Epic roles, break-glass, and the door. A technical leader can walk a healthcare customer from "we govern access by hand across HR, the Medical Staff Office, and Epic" to "one identity truth, continuously governed, with real-time revoke."

โ† related: Ownership & category model (page 2)  ยท  the validation deck โ†’