Shared med-surg workstation
Day-shift RN finishes documentation and uses Log Off so night staff cannot open mid-session notes under the wrong identity — AC-12(1) makes that control available and effective.
AC-12(1) enhances base AC-12 session termination by providing a logout capability for user-initiated communications sessions whenever authentication is used to gain access. Healthcare shared workstations, dictation booths, and kiosk-style EHR launches need an obvious, reliable Log Off that ends the session and clears credentials — not merely minimizing the window or locking while leaving another user’s chart context recoverable.
Give users a clear, working logout that fully terminates authenticated ePHI sessions so the next person cannot resume another user’s clinical context.
How this control shows up in healthcare and HIPAA-covered environments.
Day-shift RN finishes documentation and uses Log Off so night staff cannot open mid-session notes under the wrong identity — AC-12(1) makes that control available and effective.
ROI clerks handle highly sensitive disclosures. Explicit logout at shift end destroys the session rather than leaving a locked screen that a coworker might unlock with a shared pattern.
After a video visit, the provider logs out of the telehealth+EHR SSO session before the next clinician uses the same cart.
Auditors ask how shared workstations prevent user mix-ups. A working user-initiated logout plus training evidence supports AC-12(1); lock-only habits on shared PCs are a common gap.
How this NIST control supports HIPAA Security Rule expectations.
Base AC-12 requires session termination under defined conditions; AC-12(1) specifically requires a user-initiated logout capability for authenticated sessions.
Lock may suffice for single-user offices; shared clinical devices generally need explicit logout between users.
Only if it fully terminates the authenticated session. Persistent SSO cookies often mean it does not — verify behavior.
Related controls that commonly accompany AC-12(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.