Shadow TeamViewer on PACS station
A tech installs personal remote tools for ‘after-hours fixes.’ AC-17(3) application control removes it; support must use the managed vendor gateway.
AC-17(3) enhances base AC-17 by routing remote access through managed access control points. Shadow VPNs, ad-hoc RDP, personal TeamViewer, and modem-era backdoors bypass monitoring and encryption standards. Healthcare environments must force telework, telehealth admin, and vendor support through known concentrators, ZTNA brokers, or PAM gateways where policy, MFA, and logging apply.
Ensure all remote access to systems that handle ePHI enters only via organization-managed control points — not unmanaged peer-to-peer or direct exposures.
How this control shows up in healthcare and HIPAA-covered environments.
A tech installs personal remote tools for ‘after-hours fixes.’ AC-17(3) application control removes it; support must use the managed vendor gateway.
Legacy NAT rule is replaced with VPN + PAM jump host — the only managed control point into the billing SQL host with ePHI.
Three clinics ran their own SOHO VPNs. Consolidation onto the enterprise concentrator restores managed AC-17(3) points and consistent MFA.
Auditors map internet-facing services and ask which remote paths exist. Undocumented entry points are critical AC-17(3) findings in healthcare networks.
How this NIST control supports HIPAA Security Rule expectations.
Treat the IdP/SSO and conditional-access layer as the managed point — document it and prevent bypass via local accounts where possible.
Only if it is inventoried, hardened, monitored, and approved as a managed point — not an informal SOHO router.
AC-17(3) forces traffic through managed gateways; AC-17(1) monitors and controls sessions on those (and related) paths.
Related controls that commonly accompany AC-17(3).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.