AC-17 Access Control

Remote Access

High Risk Moderate Medium Cost

AC-17 requires establishing and documenting usage restrictions, configuration requirements, connection requirements, and implementation guidance for each type of remote access allowed, authorizing remote access before connections are established, and monitoring remote access for unauthorized use. For clinics and hospitals this covers VPN, secure virtual desktops, EHR vendor remote tools, and telehealth clinician access to ePHI from off-site locations.

Control Objective

Allow remote work and telehealth without opening unmanaged pathways into systems that store or process ePHI — every remote method is authorized, configured, monitored, and revokeable.

Implementation Guidance

  1. Inventory every remote access method: corporate VPN, always-on tunnel, VDI/AVD, vendor remote support (BeyondTrust, LogMeIn Rescue, etc.), EHR cloud SSO from home, RDP gateways, and SSH jump hosts.
  2. Write usage rules per method (who may use it, from which devices, for what purpose, approved hours if needed).
  3. Require MFA for all interactive remote access to networks or apps with ePHI.
  4. Prefer managed, compliant endpoints (MDM/EDR) or VDI that keeps ePHI off personal disks.
  5. Segment remote users: clinical apps only — not flat access to the entire clinic LAN.
  6. Log session start/stop, source IP, user, and destination; alert on impossible travel and new-country logons.
  7. Authorize vendor remote sessions case-by-case with time limits and session recording where feasible.
  8. Disable unused remote protocols (legacy PPTP, open RDP to the internet) and review AC-17 annually after telehealth growth.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Home-based medical coder on personal Wi-Fi

A coder needs EHR access from home. Instead of exposing RDP to the internet, AC-17 drives a VPN + MFA + company laptop (or VDI) policy so charts never land on an unmanaged PC, and sessions are logged for audit.

EHR vendor emergency patch

The EHR hoster requests remote admin access after hours. AC-17 requires a ticket, named engineer account, time-boxed approval, and monitoring — not a standing shared support login permanently allowed through the firewall.

Telehealth provider between clinics

A physician sees patients via telehealth while traveling. Remote access is limited to the telehealth + EHR web apps through SSO with MFA; split-tunnel VPN to the whole clinical VLAN is denied by policy.

Best Practices

  • Ban direct RDP/SSH exposure to the public internet.
  • Enforce MFA and device health checks before VPN admission.
  • Use just-in-time vendor remote access with logging.
  • Keep an authoritative inventory of remote access gateways.
  • Pair AC-17 with AC-10/11/12 session limits, locks, and termination.
  • Test revoke paths: can you kill a remote session in minutes during an incident?

Common Gaps & Violations

  • Personal PCs remoting into EHR via shared passwords and no MFA.
  • Always-on vendor support tunnels with no ticket trail.
  • Split-tunnel VPN allowing lateral movement to imaging and file servers.
  • No monitoring of remote session volume or geography.
  • Remote access policy that only mentions VPN while ignoring SaaS EHR browser access.

Required Documentation

  • Remote access policy and approved methods list
  • Configuration standards (VPN, VDI, MFA, posture)
  • Vendor remote access procedure and sample tickets
  • Network diagrams showing remote entry points and segmentation
  • Monitoring/alerting rules for remote sessions

How to Test & Validate

  1. Attempt remote access without MFA; confirm deny.
  2. Verify unmanaged device is blocked or forced into a restricted VDI path.
  3. Sample vendor remote sessions for authorization tickets and time bounds.
  4. Confirm remote users cannot reach unauthorized VLANs.
  5. Review SIEM for remote access anomalies over 30 days.

Audit Considerations

Auditors map remote access to HIPAA transmission and access controls. Expect demos of MFA, device requirements, and evidence that vendor remote tools are controlled — not just a VPN screenshot.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — remote pathways must still limit access to authorized users.
  • 164.312(d) Person or Entity Authentication — MFA for remote access supports authentication strength.
  • 164.312(e) Transmission Security — integrity and encryption of ePHI in transit over remote links.
  • 164.308(a)(1) Risk Analysis — remote work and telehealth are high-frequency risks requiring documented treatment.

Compliance Tips

  • Treat browser-based EHR from home as remote access under AC-17, even without a classic VPN.
  • Add remote-access checks to new telehealth program launches.
  • Require BA remote-support terms in contracts and BAAs.

Frequently Asked Questions

Is VPN mandatory for AC-17?

No. AC-17 requires authorized, controlled remote methods. VDI or SSO to a hardened cloud EHR can qualify if risks are managed — but unmanaged home PCs with direct EHR logins usually do not.

How does AC-17 differ from AC-19?

AC-17 covers the remote connection method and usage rules. AC-19 focuses on the mobile device itself (phone/tablet/laptop controls).

Do business associates need AC-17 if they only use our cloud EHR?

If they access ePHI remotely through your systems or theirs, remote access risks still apply — cover expectations in the BAA and their security program.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17 Remote Access
  • NIST SP 800-46 Guide to Enterprise Telework / Remote Access Security
  • HIPAA Security Rule §§ 164.312(a), 164.312(d), 164.312(e)
  • Related controls: AC-19, AC-20, IA-2, AC-10, SC-7, SC-8

Need Help Implementing AC-17?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.