Same-day termination procedure
Procedure requires EHR disable within four hours of involuntary termination with after-hours contacts listed.
AC-1(2) enhances AC-1 by focusing on access control procedures enhancement. Operationalize procedures for account requests, approvals, reviews, and termination support so policy is executable for EHR and related systems. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Enhance access control procedures that support consistent account and access management for systems handling ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Procedure requires EHR disable within four hours of involuntary termination with after-hours contacts listed.
Clinic managers use a standard procedure mapping job roles to EHR packs — no free-text 'give full access'.
IAM follows documented steps to export EHR entitlements, send manager attestations, and revoke leftovers.
Assessors look for operating evidence of Access Control Procedures Enhancement on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-1(2).
How this NIST control supports HIPAA Security Rule expectations.
Policy states requirements; procedures give step-by-step for requests, reviews, and terminations.
They must be executable by IAM/service desk with SLAs and system steps.
Completed request tickets, review packets, and termination checklists.
Related controls that commonly accompany AC-1(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.