< Back

Assign Roles

Health Gorilla enforces access controls through role-based permissions assigned at the user level. Each user account is granted a role such as Doctor, Nurse, or Staff, which determines the API actions and features available to that user. Role assignment is managed during onboarding and can be updated by request.

Roles align with HIPAA-defined job functions and support least-privilege access for sensitive operations like ordering, messaging, and record retrieval.

Common Roles and Capabilities

RoleDescriptionExample Permissions
DoctorLicensed provider with full clinical accessQuery patient data, submit orders
NurseClinical staff with partial accessView patient data, assist in care
StaffNon-clinical personnel with limited accessVerify demographics, submit referrals
SupportTechnical or admin users with restricted capabilitiesMonitor API activity, troubleshoot

To assign or update user roles

  1. Submit a request to Health Gorilla Support identifying the user and desired role.
  2. Confirm that the role aligns with the user’s job function and permitted use case.
  3. Health Gorilla will validate and apply the role change.

Role-based access must align with your organization’s security policy and data use agreement. Unauthorized role escalation may result in access revocation.