AC-10(1) Access Control

Concurrent Session Control by Account Type

High Risk Moderate Medium Cost

AC-10(1) enhances AC-10 by focusing on concurrent session control by account type. Limit concurrent sessions by account type (stricter for privileged/EHR security admins; controlled limits for shared-floor clinical workflows). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Control the number of concurrent sessions for account types that can access ePHI, with stricter limits for privileged accounts.

Implementation Guidance

  1. Define concurrent session limits by account type.
  2. Apply strictest limits to privileged/EHR security admins.
  3. Tune clinician limits with informatics for mobility.
  4. Prohibit unlimited sessions for generic/shared accounts.
  5. Enforce via IdP/EHR session policy.
  6. Alert on limit violations or forced kills.
  7. Document clinical exceptions.
  8. Retest after EHR upgrades.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Privileged admin single session

EHR security-admin account limited to one concurrent session; second logon kills or denies the prior.

Standard clinician limit

Floor nurses allowed limited concurrent sessions for ROVR/workstation realities; still capped.

Shared kiosk account banned

Generic shared accounts cannot open multiple concurrent ePHI sessions across units.

Best Practices

  • Tie AC-10(1) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims concurrent session control by account type but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Concurrent Session Control by Account Type (AC-10(1))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to concurrent session control by account type; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Concurrent Session Control by Account Type on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-10(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit concurrent abuse of sessions to ePHI.
  • 164.312(a)(2)(iii) Automatic Logoff — complements session discipline.
  • 164.308(a)(1) Risk Management — session hijacking/sharing risks.
  • 164.312(b) Audit Controls — concurrent session anomalies should be reviewable.

Compliance Tips

  • List AC-10(1) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

One session for everyone?

No — vary by account type; privileged stricter than standard clinical.

Break clinical mobility?

Tune clinician limits with informatics; still avoid unlimited concurrent sessions.

How enforce?

IdP/EHR session policies and admin console settings.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-10(1)
  • Related controls: AC-10, AC-2, AC-3

Need Help Implementing AC-10(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.