Downtime break-glass board
Enabling read-only downtime board without normal auth requires dual authorization from house supervisor and IT.
AC-14(1) enhances AC-14 by focusing on dual authorization. Require dual authorization before permitting specific actions without normal identification/authentication (emergency downtime workflows). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Enforce dual authorization for organization-defined permitted actions that bypass standard identification or authentication.
How this control shows up in healthcare and HIPAA-covered environments.
Enabling read-only downtime board without normal auth requires dual authorization from house supervisor and IT.
Special permitted action to unlock emergency workstation image needs two authorized roles.
Temporary census workflow without full auth requires dual authorization and after-action review.
Assessors look for operating evidence of Dual Authorization on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-14(1).
How this NIST control supports HIPAA Security Rule expectations.
Only for rare permitted actions (e.g., certain downtime) and still dual-authorized.
Related idea; here dual auth gates permitted actions that skip normal identification/authentication.
Yes — review every use.
Related controls that commonly accompany AC-14(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.