The interdisciplinary group meeting is the clinical and ethical centre of hospice care — the regular gathering where physician, nurse, social worker, chaplain, aide, and bereavement coordinator review each patient's status, address symptom management challenges, support each other in the emotional work of end-of-life care, and update the care plan that guides the patient's remaining time. The documentation generated by these meetings — and by the individual encounters that feed into them — is among the most intimate, multidimensional, and sensitive patient information in all of healthcare.
It is also among the most insecurely managed. In my experience assessing hospice HIPAA programmes, IDG documentation is often the least well-governed information category in the hospice EHR: accessed by every clinical user regardless of their specific care relationship with individual patients; stored in a section of the record that receives no more access restriction than routine nursing visit notes; and sometimes maintained in separate documents — meeting minutes, chaplaincy logs, bereavement assessment forms — that are stored outside the EHR without the access controls the EHR provides.
The gap between the sensitivity of IDG documentation and the security of its governance is not the result of negligence. It is the result of EHR configuration that was done for clinical workflow convenience rather than minimum necessary compliance, and the absence of a specific protocol for the most complex information sharing challenge in hospice: when something disclosed in a confidential pastoral or social work encounter needs to reach the clinical team without exposing the full spiritual or psychosocial record to every IDG member.
What IDG Documentation Contains — and Why It Requires More Than Standard PHI Protection
A complete IDG documentation record for a hospice patient over a 90-day care episode contains content from disciplines whose sensitivity varies significantly and whose access requirements therefore differ:
• Physician assessments and prognosis updates: clinical documentation that the full care team needs access to for coordinated care delivery. Standard clinical access profiles are appropriate for this content.
• Nursing symptom management narratives and functional status observations: clinical documentation required by the full care team. Standard clinical access profiles apply.
• Social work psychosocial assessments: family system analysis, financial concerns, housing situation, advance directive status, history of family conflict, and mental health concerns. This content is significantly more sensitive than routine clinical notes and warrants restricted access beyond the nurse and physician.
• Chaplaincy and spiritual care notes: what the patient has shared in pastoral encounters — expressed fears, religious doubts, relationship conflicts, unfinished life business, and final wishes. This is the most sensitive content category in the hospice record. It was shared in a context analogous to religious confession and warrants the most restrictive access profile.
• Aide personal care observations and family interaction notes: observations from the aide's visits that inform the care team's understanding of the home environment and family dynamics. Moderate sensitivity — accessible to clinical staff but not to billing or administrative staff.
• Bereavement coordinator pre-death family assessments: the assessment that will guide bereavement support after the patient's death, including identification of at-risk family members and anticipated grief complications. Sensitive content that should be accessible to the bereavement programme team but not to the full clinical care team after the patient's death.
A single EHR access profile that grants the same level of access to all of these content categories for every clinical user fails the minimum necessary standard that HIPAA requires. The standard demands that access be limited to the information each user needs for their specific role — which for a hospice IDG means different content categories for different disciplines.
The Role-Based Access Framework for IDG Records
Configuring Access by Discipline
The access control architecture for IDG records should reflect four distinct access tiers, each corresponding to a set of IDG roles with similar information needs:
• Tier 1 — Clinical Oversight (Physician, Director of Nursing, Clinical Supervisor): full IDG record access across all patient cases, with audit logging of all access events. This tier requires broad access because oversight responsibility extends across the full patient census and all care domains.
• Tier 2 — Primary Care Team (Primary Nurse, Primary Social Worker): full access to IDG records for their assigned patient caseload. Access to IDG summary information — but not full narrative notes — for patients outside their caseload when clinical coverage requires temporary access. Access to this expanded coverage should be logged as a coverage access event distinct from routine primary caseload access.
• Tier 3 — Discipline-Specific Access (Chaplain, Music Therapist, Volunteer Coordinator, Aide): access to their own discipline's documentation plus the care plan for their assigned patients. No access to social work psychosocial assessments, chaplaincy notes from other clinicians, or bereavement pre-death assessments unless specifically granted through the Tier 1 override process.
• Tier 4 — Administrative and Billing: access to patient demographic, scheduling, and billing information. No access to clinical narrative documentation, social work assessments, chaplaincy notes, or bereavement assessments. The minimum necessary standard applied most strictly — billing coordinators have no clinical need for psychosocial or spiritual care documentation.
Chaplaincy Access: The Special Case
Chaplaincy documentation requires specific handling beyond the four-tier framework. The pastoral relationship creates a confidentiality expectation that is closer to the attorney-client or priest-penitent relationship than to the standard patient-clinician relationship. Hospice chaplains document what patients share in the absolute trust that it will be held with the same discretion that religious confession is held.
Configure chaplaincy notes as a distinct note type within the EHR — "Spiritual Care" or "Pastoral Care" — with a restricted access profile that limits visibility to: the documenting chaplain, the director of chaplaincy services (or clinical supervisor with oversight responsibility), and the physician and nurse practitioner who integrate spiritual care assessment into the overall care plan. All other care team members — including other chaplains not assigned to this patient — should not have default access to chaplaincy note content.
EHR-Specific Configuration Guidance for Major Hospice Platforms
Axxess Hospice
Axxess Hospice supports role-based access configuration through its administrative settings panel. To configure discipline-specific access restrictions for IDG documentation:
• Navigate to Administration > Security > User Roles. Create role profiles that reflect each IDG discipline — do not rely on the default role profiles, which are configured for broad access.
• For the Chaplain role, restrict document type access to Spiritual Care notes, Care Plan, and IDG Meeting Summary. Remove access to Social Work Assessment, Psychosocial Evaluation, and Bereavement Assessment document types.
• For Aide roles, restrict access to Aide Visit Note, Care Plan, and Task List. Remove access to all narrative assessment document types including Social Work, Chaplaincy, and Bereavement.
• Enable the document-level audit log in Axxess by navigating to Administration > Audit Settings and confirming that document access events are captured with user identity, timestamp, and document type. Set audit log retention to meet the HIPAA six-year documentation retention requirement.
• Contact Axxess support to confirm the current version supports note-type-level access restriction — Axxess updates its permission architecture periodically and configuration guidance may vary by version.
Brightree Hospice
Brightree supports role-based access configuration through its security administration module. Brightree's permission architecture operates at the module and document type level, making discipline-specific IDG access restriction achievable with deliberate configuration:
• In Brightree's Security Administration, create custom security roles for each IDG discipline rather than using the default clinical user role. The default clinical user role grants broad access across all clinical document types.
• For the Spiritual Care / Chaplaincy role, configure document type permissions to include Spiritual Care Notes and Care Plan access, excluding Social Work Assessment, Psychosocial Evaluation, and Bereavement documents.
• Brightree supports SSO integration that centralises access management — implement SSO so that Brightree access lifecycle is managed through the identity provider rather than through individual Brightree account management. This ensures that access is terminated when staff leave without requiring a separate Brightree deactivation step.
• Brightree's audit logging captures document access events by default. Confirm the log retention period in your Brightree administrative settings and extend it if the default does not meet the HIPAA six-year documentation retention requirement.
MatrixCare Hospice
MatrixCare's permission architecture is more granular than most hospice EHR platforms, supporting access restriction at the note category and document type level. This granularity is an advantage for IDG access control configuration but requires more deliberate setup:
• In MatrixCare's User Management module, create discipline-specific permission sets rather than using the default clinical permission set. The default clinical permission set in MatrixCare grants access to all clinical documentation categories.
• For the Chaplaincy permission set, configure document type access to include only Pastoral Care / Spiritual Care notes and Care Plan documents. The MatrixCare documentation explicitly supports note-type-level restriction through its category permission framework.
• MatrixCare's multi-setting architecture — which serves SNF and assisted living alongside hospice — requires explicit confirmation that the hospice permission sets do not inherit permissions from other care setting configurations within the same MatrixCare deployment. Cross-setting permission inheritance is a consistent gap in multi-setting MatrixCare implementations.
• MatrixCare's audit log module captures access events at the document and field level. Enable field-level audit logging for the most sensitive document categories — Chaplaincy, Social Work Assessment, and Bereavement — to capture not just that a document was accessed but what specific fields were viewed.
The Cross-Discipline Information Sharing Protocol: When Pastoral Information Must Reach the Clinical Team
The most operationally challenging scenario in IDG documentation security is the one that arises regularly in hospice care: a chaplain, during a pastoral encounter, learns something that has direct clinical significance. The patient expresses a desire to hasten death. A family member describes a plan to withhold medication after the patient is transferred to inpatient care. The patient discloses a physical symptom they have been concealing from the nursing team. These are not purely spiritual concerns — they are clinical safety issues that require immediate communication to the care team.
The access control configuration that restricts chaplaincy notes from routine clinical view cannot also prevent this clinically necessary communication. The solution is a structured cross-discipline information sharing protocol that protects the confidentiality of the pastoral relationship while ensuring clinical safety information reaches the team members who need it.
The Protocol
• Step 1 — Clinical concern identification: the chaplain determines that information disclosed in a pastoral encounter has direct clinical safety significance requiring team awareness.
• Step 2 — Verbal communication to clinical lead: the chaplain communicates the clinically relevant information verbally or through a secure message directly to the primary nurse or clinical supervisor — not through the chaplaincy note, which would create a documentation trail that other IDG members could access through the note system.
• Step 3 — Clinical note entry: the primary nurse or clinical supervisor documents the clinically relevant information in a clinical note under their own authorship, without referencing the pastoral encounter as the source. "Patient expressed concern about hastening death during today's IDG visit" — not "Chaplain reported that patient expressed concern during pastoral visit."
• Step 4 — Chaplaincy note documentation: the chaplain may document the pastoral encounter in the restricted chaplaincy note system, including the fact that clinical information was communicated to the care team, without identifying the specific content that was shared. "Clinical safety concern communicated to nursing team per protocol" — not the content of the concern.
• Step 5 — Supervisory notification: for clinical safety concerns of significant severity — active suicidal ideation, disclosed intent to harm — the chaplain notifies the director of chaplaincy services and the clinical supervisor simultaneously, with documentation of the notification in the supervisory communication log.
This protocol preserves the pastoral relationship's confidentiality at the documentation level while ensuring that clinical safety information reaches the team members responsible for acting on it. It requires that every hospice chaplain understand and practise the protocol — which means it must be included in chaplaincy onboarding and addressed in the annual HIPAA training that chaplains receive.
The IDG Audit Log Review Protocol
IDG documentation audit logging must be reviewed on a schedule that is more frequent than the general clinical record audit log review — because the sensitivity of IDG content warrants heightened monitoring. A quarterly review of IDG documentation access events is the standard I recommend for most hospice organisations; monthly review is appropriate for organisations where a prior access control breach has been identified.
What the Quarterly Review Covers
The quarterly IDG audit log review should examine five specific anomaly patterns:
• Access to chaplaincy notes by users outside the restricted access profile: any access to spiritual care documentation by users who are not in the chaplain, director of chaplaincy services, physician, or nurse practitioner roles. Each instance requires investigation — either a permission configuration error or an access control violation.
• Access to social work psychosocial assessments by billing or administrative staff: billing and administrative users should have no access to narrative clinical assessments. Any access event of this type is either a permission configuration error or an anomalous access event requiring investigation.
• After-hours access to IDG narrative documentation by users without documented on-call responsibility: a social worker accessing social work psychosocial assessments at 11pm on a Saturday who is not the documented on-call social worker is an anomalous access pattern warranting investigation.
• Large volume access to IDG records for patients outside a user's normal caseload: a nurse who accesses IDG records for 40 patients in a single session, 35 of whom are not on her assigned caseload, is exhibiting a data access pattern inconsistent with routine clinical use.
• Access to bereavement pre-death assessment records by users without bereavement programme responsibility: bereavement assessments are sensitive documents that should be accessible to the bereavement programme team and clinical supervisors with oversight responsibility — not to the full clinical care team after the patient's death.
Documentation and Escalation
Each anomalous access event identified in the quarterly review should be documented in the HIPAA access control review log with: the date of the access event, the accessing user's name and role, the document accessed, the investigation findings (legitimate access with a documented clinical rationale, permission configuration error requiring correction, or access control violation requiring escalation), and the corrective action taken. Access control violations — confirmed inappropriate access to restricted IDG documentation — must be escalated to the HIPAA Security Officer and addressed under the sanctions policy.
ShieldForce configures IDG documentation access controls as a standard component of every hospice managed service engagement — discipline-specific role profiles, chaplaincy note restriction, cross-discipline information sharing protocol documentation, and quarterly audit log review. The configuration is adapted for whichever hospice EHR platform your organisation uses. Start with a free assessment.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Hospice Cybersecurity — shieldforce.io/hospice-cybersecurity
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

