Control Objective
Prevent a single account from maintaining an unlimited number of simultaneous sessions, lowering the impact of credential theft, session hijacking, and informal password sharing in clinical environments.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Stolen VPN password used from two countries
A practice manager's VPN account allows unlimited concurrent sessions. An attacker logs in from abroad while she works from home — both sessions stay active. With AC-10 set to one VPN session, the second logon is blocked or drops the first, producing an immediate help-desk call and investigation.
EHR 'sticky' sessions across clinics
A floating nurse works Monday at Clinic A and Tuesday at Clinic B. Without session controls, yesterday's session may remain open on a shared PC. A concurrent limit of one interactive EHR session, combined with AC-11/AC-12 lock and terminate policies, closes abandoned sessions when she signs on elsewhere.
Privileged cloud EMR admin
The EMR configuration admin role is limited to a single concurrent console session. That stops a phished admin password from being used in parallel with the legitimate change window, and forces clearer operational discipline around who is 'on console.'
Audit Considerations
Auditors will ask for the defined numeric limits, where they are enforced, and proof from configuration — not screenshots of a policy PDF alone. Be prepared to explain clinical workflow exceptions and how accountability is preserved.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.312(a)(1) Access Control — unique user identification and emergency access procedures sit alongside session controls that keep access only with authorized persons.
- 164.312(a)(2)(iii) Automatic Logoff — HIPAA's addressable automatic logoff pairs operationally with AC-10/AC-11/AC-12 session management.
- 164.312(d) Person or Entity Authentication — limiting concurrent sessions reduces abuse of authenticated sessions.
- 164.308(a)(1) Risk Management — parallel session abuse should appear in risk analysis for remote access and shared clinical workstations.