Controlling staff access to patient records

How can I control what patients users can see in the EMR? We have patient studies and the clinician that is part of the study should only see the patients record who is assigned to the study.