Annual policy acknowledgment
All EHR users must acknowledge the updated access control policy before badge reactivation each year.
AC-1(1) enhances AC-1 by focusing on access control policy enhancement. Disseminate and acknowledge an access control policy covering workforce, BA users, and ePHI systems — with version control and annual review. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Enhance access control policy management so healthcare workforce receive current policy requirements for ePHI access.
How this control shows up in healthcare and HIPAA-covered environments.
All EHR users must acknowledge the updated access control policy before badge reactivation each year.
Contract coders receive and attest to the access control policy before IdP accounts are enabled.
Security publishes policy v3.2 tightening remote access language; intranet shows current version only.
Assessors look for operating evidence of Access Control Policy Enhancement on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-1(1).
How this NIST control supports HIPAA Security Rule expectations.
Distribute, version, and capture acknowledgment for workforce with ePHI access.
Yes — anyone accessing ePHI systems should receive applicable policy.
At least annually and after significant incidents or regulatory change.
Related controls that commonly accompany AC-1(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.