AC-1(2) Access Control

Access Control Procedures Enhancement

High Risk Easy Low Cost

AC-1(2) enhances AC-1 by focusing on access control procedures enhancement. Operationalize procedures for account requests, approvals, reviews, and termination support so policy is executable for EHR and related systems. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Enhance access control procedures that support consistent account and access management for systems handling ePHI.

Implementation Guidance

  1. Document step-by-step account request and approval procedures.
  2. Define termination/disable SLAs including after-hours.
  3. Map job roles to standard EHR entitlement packs.
  4. Write quarterly access review runbooks with evidence retention.
  5. Include contractor and student procedures.
  6. Train service desk on identity proofing for unlocks.
  7. Align procedures with IdP/EHR actual screens.
  8. Review procedures annually with IAM and privacy.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Same-day termination procedure

Procedure requires EHR disable within four hours of involuntary termination with after-hours contacts listed.

Access request form to RBAC packs

Clinic managers use a standard procedure mapping job roles to EHR packs — no free-text 'give full access'.

Quarterly access review runbook

IAM follows documented steps to export EHR entitlements, send manager attestations, and revoke leftovers.

Best Practices

  • Tie AC-1(2) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims access control procedures enhancement but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Access Control Procedures Enhancement (AC-1(2))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to access control procedures enhancement; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Access Control Procedures Enhancement on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-1(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.316 Policies and Procedures — implement reasonable/appropriate policies and procedures.
  • 164.308(a)(4) Information Access Management — access policies for ePHI.
  • 164.308(a)(5) Workforce Security Awareness — disseminate expectations.
  • 164.312(a)(1) Access Control — policy drives technical access measures.

Compliance Tips

  • List AC-1(2) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Policy vs procedure?

Policy states requirements; procedures give step-by-step for requests, reviews, and terminations.

Must procedures be technical?

They must be executable by IAM/service desk with SLAs and system steps.

Evidence?

Completed request tickets, review packets, and termination checklists.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-1(2)
  • Related controls: AC-1, AC-2, IA-4

Need Help Implementing AC-1(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.