On-call DBA from home
Production ePHI DB changes require PAM check-out over VPN with recording — not direct SQL from a personal laptop admin account.
AC-17(4) enhances base AC-17 by authorizing the execution of privileged commands and access to security-relevant information via remote access only for specified organizational needs, and by documenting the rationale. Domain admins remoting from home into EHR databases, or vendors elevating on clinical hosts, must be explicitly allowed, time-bounded, and justified — not a standing convenience for every IT staffer.
Permit privileged remote operations on ePHI-related systems only when justified, approved, and constrained — never as unrestricted default remote admin.
How this control shows up in healthcare and HIPAA-covered environments.
Production ePHI DB changes require PAM check-out over VPN with recording — not direct SQL from a personal laptop admin account.
Role config changes from a conference hotel only via VDI PAW; AC-17(4) documents why remote privileged access is allowed for this job and under what device rules.
OEM gets time-limited privileged remote through the managed gateway for a PACS host; standing root VPN is denied.
Ask who can run privileged commands remotely into ePHI systems. Broad standing admin VPN without documented need fails AC-17(4).
How this NIST control supports HIPAA Security Rule expectations.
Clinical charting is not privileged admin. Privileged remote means security-relevant or administrative commands — keep those rare and controlled.
MFA is necessary but not sufficient; you still need authorization limits, documentation of need, and preferably command control/recording.
Yes — treat cloud admin as privileged remote access with the same rigor.
Related controls that commonly accompany AC-17(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.