Impossible-travel VPN
A coder’s VPN appears from two states an hour apart. AC-17(1) alerting lets SOC disable the tunnel before bulk claim exports complete.
AC-17(1) enhances base AC-17 by employing automated mechanisms to monitor and control remote access methods. Authorizing VPN or vendor tools is not enough — healthcare organizations must see who is connected, from where, to which ePHI systems, and be able to disconnect or block abusive sessions in near real time during incidents or anomalous telehealth/VPN activity.
Continuously monitor remote connections that can reach ePHI and retain the ability to control (allow, limit, or terminate) those sessions when risk warrants.
How this control shows up in healthcare and HIPAA-covered environments.
A coder’s VPN appears from two states an hour apart. AC-17(1) alerting lets SOC disable the tunnel before bulk claim exports complete.
EHR hoster remote session exceeds the approved window. Monitoring flags the still-open channel; ops terminate and require a new ticket.
Sudden surge of failed remote SSO into the telehealth EHR triggers control rules that step-up MFA and temporary geo-blocks.
Assessors ask how you detect unauthorized remote use. Show live dashboards, alert examples, and evidence you can disconnect — policy text alone fails AC-17(1).
How this NIST control supports HIPAA Security Rule expectations.
Weakly at best. The enhancement expects automated monitoring and control — detection plus ability to act.
No. Focus on anomalous patterns, privileged remote admin, and vendor paths; retain logs for routine clinical access.
SI-4 is broader system monitoring; AC-17(1) specifically targets remote access methods.
Related controls that commonly accompany AC-17(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.