Control Objective
Ensure unattended authenticated sessions cannot be used or viewed by others without re-authentication, protecting on-screen ePHI and system integrity.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Registration desk shoulder surfing
A front-desk clerk steps away to help a patient with paperwork. Without session lock, the next visitor can read demographics and insurance details on screen. A 3-minute idle lock plus staff habit of manual lock prevents exposure.
ED trauma bay workstation
Emergency department PCs need fast access. The organization uses short locks with badge tap-in rather than long passwords typed each time — meeting AC-11 intent without slowing care.
Laptop left in a clinic conference room
A care manager's laptop auto-locks after 5 idle minutes during a meeting break, blocking access to care-plan documents if another attendee tries the keyboard.
Audit Considerations
HIPAA assessors frequently sample workstations on the floor. They look for effective lock behavior in real workflows, not only a GPO screenshot. Be ready to explain clinical timeout exceptions.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.312(a)(2)(iii) Automatic Logoff — addressable implementation specification closely aligned with AC-11/AC-12.
- 164.310(b) Workstation Use and
- 164.310(c) Workstation Security — physical surroundings of workstations displaying ePHI.
- 164.312(a)(1) Access Control — session lock is a technical procedure supporting limited access.