AC-17(2) Access Control

Protection of Confidentiality and Integrity Using Encryption

High Risk Moderate Medium Cost

AC-17(2) enhances base AC-17 by implementing cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. Healthcare remote paths — site-to-site and client VPN, HTTPS EHR, virtual desktops, and vendor support tunnels — must use strong, modern encryption so ePHI cannot be sniffed or altered on home Wi-Fi, hotel networks, or intermediate links.

Control Objective

Encrypt remote access sessions that carry or can reach ePHI so confidentiality and integrity are preserved end-to-end for authorized remote work and support.

Implementation Guidance

  1. Require TLS 1.2+ (prefer 1.3) for web EHR, patient portals, and telehealth; disable weak ciphers.
  2. Use modern VPN protocols (e.g., IKEv2/IPsec or WireGuard-class enterprise equivalents) with strong algorithms; ban PPTP/legacy SSL VPN weak suites.
  3. Encrypt VDI/display protocols; avoid cleartext RDP to the internet.
  4. Mandate encryption for vendor remote-support tools; prohibit unencrypted screen-share into ePHI hosts.
  5. Manage certificates properly; monitor expiry on remote gateways.
  6. Prefer full-tunnel or application-level ZTNA that keeps clinical traffic protected.
  7. Document FIPS-validated modules where federal or contractual requirements apply.
  8. Retest cipher posture after appliance upgrades.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Home coder on café Wi-Fi

Without AC-17(2), a weak VPN could expose claim screens. Enforced modern VPN crypto protects the ePHI session on untrusted networks.

Telehealth video+EHR

Telehealth platform and embedded EHR launch use TLS only; outdated protocol versions are blocked at the reverse proxy.

Vendor RDP historically exposed

Legacy open RDP is replaced with an encrypted PAM gateway — integrity and confidentiality of the admin session into the interface engine.

Best Practices

  • Maintain a remote-access cipher baseline.
  • Disable obsolete protocols/ciphers quarterly.
  • Encrypt both authentication and session payloads.
  • Monitor certificate health on gateways.
  • Pair encryption with MFA (IA-2).
  • Include mobile telehealth apps in crypto testing.

Common Gaps & Violations

  • Split-tunnel sending EHR traffic outside the encrypted tunnel.
  • TLS 1.0 still enabled on patient portal.
  • Vendor tools using proprietary weak crypto.
  • Cleartext RDP published ‘temporarily’ forever.
  • Expired certificates forcing users to click through warnings.

Required Documentation

  • Remote access encryption standard (AC-17(2))
  • Approved protocols/cipher suites
  • Architecture diagrams for VPN/VDI/telehealth crypto
  • Certificate management procedure
  • Scan/test results for gateway posture

How to Test & Validate

  1. SSL/TLS scan remote portals; confirm weak versions fail.
  2. Verify VPN rejects deprecated proposals.
  3. Confirm no cleartext remote admin paths to ePHI hosts.
  4. Inspect split-tunnel rules for ePHI destinations.
  5. Review certificate expiry monitoring alerts.

Audit Considerations

HIPAA transmission security assessors expect evidence of encryption in transit for remote ePHI access — cipher inventories and scan results beat marketing claims about “secure VPN.”

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(e)(1) Transmission Security — guard against unauthorized access to ePHI transmitted over networks.
  • 164.312(e)(2)(ii) Encryption — addressable encryption of ePHI in transit; AC-17(2) operationalizes it for remote access.
  • 164.312(e)(2)(i) Integrity Controls — protect transmitted ePHI from improper modification.
  • 164.312(a)(1) Access Control — remote encrypted channels still bind to authorized users.

Compliance Tips

  • Map AC-17(2) explicitly to HIPAA transmission encryption in the SSP.
  • Re-validate after every VPN or WAF change.
  • Do not forget API and HL7/HTTPS interfaces used remotely by vendors.

Frequently Asked Questions

Is HTTPS to cloud EHR enough without a VPN?

It can satisfy encryption-in-transit if TLS is strong and access controls are sound; still address device and authorization risks under AC-17/AC-19.

Does AC-17(2) require encrypting data at rest?

No — it targets remote access session confidentiality/integrity. At-rest controls are elsewhere (e.g., SC-28, AC-19 encryption enhancements).

Are site-to-site tunnels in scope?

Yes when they provide remote/organizational connectivity carrying ePHI between sites or to cloud.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(2)
  • NIST SP 800-52 / 800-46 remote & TLS guidance
  • Related controls: AC-17, SC-8, SC-13, IA-2

Need Help Implementing AC-17(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.