Nursing station lock still shows banner
An RN locks the EHR but the workstation keeps the patient name and MRN in the taskbar preview. AC-11(1) forces a blank lock image so visitors cannot read demographics.
AC-11(1) enhances base AC-11 session lock by requiring the system to conceal, via the device display, information previously visible on the display with a publicly viewable image. In clinics and hospitals, a locked workstation that still shows the last chart, patient banner, or medication list fails the intent — pattern-hiding (blank, logo, or approved lock image) prevents waiting-room visitors and passersby from reading ePHI while the session remains locked for re-authentication.
When a session locks, hide all previously displayed ePHI and clinical content behind a non-informative lock screen so locked devices do not leak protected health information.
How this control shows up in healthcare and HIPAA-covered environments.
An RN locks the EHR but the workstation keeps the patient name and MRN in the taskbar preview. AC-11(1) forces a blank lock image so visitors cannot read demographics.
A locked WOW outside a trauma bay previously showed the last ECG viewer frame. Pattern-hiding replaces it with the hospital logo until badge re-auth.
Clinical messaging pushed the last VIP patient text onto the phone lock screen. MDM suppresses previews so AC-11(1) intent holds on mobile.
Surveyors observe locked workstations in corridors. A locked PC that still displays a chart is an immediate AC-11(1)/privacy finding even if password is required to resume.
How this NIST control supports HIPAA Security Rule expectations.
No. AC-11(1) specifically requires concealing previously visible information — authentication alone does not stop shoulder surfing of a frozen chart.
Yes. A static approved image or blank screen is fine; avoid any content that reveals the prior session.
Yes whenever the display can be viewed by unauthorized persons; controlled rooms may still need it if visitors or vendors enter.
Related controls that commonly accompany AC-11(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.