AC-17(3) Access Control

Managed Access Control Points

High Risk Moderate Medium Cost

AC-17(3) enhances base AC-17 by routing remote access through managed access control points. Shadow VPNs, ad-hoc RDP, personal TeamViewer, and modem-era backdoors bypass monitoring and encryption standards. Healthcare environments must force telework, telehealth admin, and vendor support through known concentrators, ZTNA brokers, or PAM gateways where policy, MFA, and logging apply.

Control Objective

Ensure all remote access to systems that handle ePHI enters only via organization-managed control points — not unmanaged peer-to-peer or direct exposures.

Implementation Guidance

  1. Inventory every remote entry path; eliminate or formally manage each.
  2. Publish approved gateways (VPN, ZTNA, VDI broker, PAM vendor portal).
  3. Block inbound RDP/SSH from the internet at the edge; allow only via managed jump/PAM.
  4. Prohibit unauthorized remote-support software on clinical endpoints via AppLocker/MDM.
  5. Segment so remote users land in controlled VLANs/app portals, not flat clinical LAN.
  6. Require architecture review before new telehealth or cloud admin paths go live.
  7. Monitor for unexpected listeners and outbound remote-access tools.
  8. Reconcile firewall objects quarterly against the approved remote-method list.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Shadow TeamViewer on PACS station

A tech installs personal remote tools for ‘after-hours fixes.’ AC-17(3) application control removes it; support must use the managed vendor gateway.

Direct RDP to clinic server

Legacy NAT rule is replaced with VPN + PAM jump host — the only managed control point into the billing SQL host with ePHI.

Multiple departmental VPN appliances

Three clinics ran their own SOHO VPNs. Consolidation onto the enterprise concentrator restores managed AC-17(3) points and consistent MFA.

Best Practices

  • One architecture pattern for remote entry where possible.
  • Deny-by-default inbound remote ports.
  • App-control against consumer remote tools.
  • Quarterly remote-path reconciliation.
  • Diagram managed points in the SSP.
  • Include cloud admin consoles as logical control points.

Common Gaps & Violations

  • Direct-to-host remote access still enabled.
  • Department-owned VPN appliances outside IT.
  • Standing vendor tunnels not through PAM.
  • Unmanaged browser plugins providing remote control.
  • No inventory of remote control points.

Required Documentation

  • Approved remote access control points list (AC-17(3))
  • Network diagrams of gateways and brokers
  • Firewall ruleset evidence
  • Application control policy for remote tools
  • Exception register with expiry

How to Test & Validate

  1. From internet, attempt direct RDP/SSH to ePHI hosts; confirm fail.
  2. Verify only documented gateways accept remote users.
  3. Scan sample endpoints for unauthorized remote-support software.
  4. Trace a vendor session — must traverse managed PAM/gateway.
  5. Reconcile firewall remote objects to inventory.

Audit Considerations

Auditors map internet-facing services and ask which remote paths exist. Undocumented entry points are critical AC-17(3) findings in healthcare networks.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — technical controls that funnel remote access through managed points.
  • 164.308(a)(4) Information Access Management — control how access is established remotely.
  • 164.312(e) Transmission Security — managed points enable consistent encryption and monitoring.
  • 164.308(a)(1) Risk Analysis — unmanaged remote paths are high residual risk.

Compliance Tips

  • Maintain a living ‘remote front door’ diagram for leadership and auditors.
  • Ban personal remote tools in AUP with technical enforcement.
  • Review new SaaS admin URLs as additional control points.

Frequently Asked Questions

Is a cloud EHR login a managed control point?

Treat the IdP/SSO and conditional-access layer as the managed point — document it and prevent bypass via local accounts where possible.

Can a clinic keep a backup VPN?

Only if it is inventoried, hardened, monitored, and approved as a managed point — not an informal SOHO router.

How does AC-17(3) differ from AC-17(1)?

AC-17(3) forces traffic through managed gateways; AC-17(1) monitors and controls sessions on those (and related) paths.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(3)
  • Related controls: AC-17, AC-17(1), SC-7, CM-7, CA-3

Need Help Implementing AC-17(3)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.