Control Objective
Allow remote work and telehealth without opening unmanaged pathways into systems that store or process ePHI — every remote method is authorized, configured, monitored, and revokeable.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Home-based medical coder on personal Wi-Fi
A coder needs EHR access from home. Instead of exposing RDP to the internet, AC-17 drives a VPN + MFA + company laptop (or VDI) policy so charts never land on an unmanaged PC, and sessions are logged for audit.
EHR vendor emergency patch
The EHR hoster requests remote admin access after hours. AC-17 requires a ticket, named engineer account, time-boxed approval, and monitoring — not a standing shared support login permanently allowed through the firewall.
Telehealth provider between clinics
A physician sees patients via telehealth while traveling. Remote access is limited to the telehealth + EHR web apps through SSO with MFA; split-tunnel VPN to the whole clinical VLAN is denied by policy.
Audit Considerations
Auditors map remote access to HIPAA transmission and access controls. Expect demos of MFA, device requirements, and evidence that vendor remote tools are controlled — not just a VPN screenshot.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.312(a)(1) Access Control — remote pathways must still limit access to authorized users.
- 164.312(d) Person or Entity Authentication — MFA for remote access supports authentication strength.
- 164.312(e) Transmission Security — integrity and encryption of ePHI in transit over remote links.
- 164.308(a)(1) Risk Analysis — remote work and telehealth are high-frequency risks requiring documented treatment.