Privileged admin single session
EHR security-admin account limited to one concurrent session; second logon kills or denies the prior.
AC-10(1) enhances AC-10 by focusing on concurrent session control by account type. Limit concurrent sessions by account type (stricter for privileged/EHR security admins; controlled limits for shared-floor clinical workflows). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Control the number of concurrent sessions for account types that can access ePHI, with stricter limits for privileged accounts.
How this control shows up in healthcare and HIPAA-covered environments.
EHR security-admin account limited to one concurrent session; second logon kills or denies the prior.
Floor nurses allowed limited concurrent sessions for ROVR/workstation realities; still capped.
Generic shared accounts cannot open multiple concurrent ePHI sessions across units.
Assessors look for operating evidence of Concurrent Session Control by Account Type on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-10(1).
How this NIST control supports HIPAA Security Rule expectations.
No — vary by account type; privileged stricter than standard clinical.
Tune clinician limits with informatics; still avoid unlimited concurrent sessions.
IdP/EHR session policies and admin console settings.
Related controls that commonly accompany AC-10(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.