AC-17(4) Access Control

Privileged Commands and Access

Critical Risk Complex High Cost

AC-17(4) enhances base AC-17 by authorizing the execution of privileged commands and access to security-relevant information via remote access only for specified organizational needs, and by documenting the rationale. Domain admins remoting from home into EHR databases, or vendors elevating on clinical hosts, must be explicitly allowed, time-bounded, and justified — not a standing convenience for every IT staffer.

Control Objective

Permit privileged remote operations on ePHI-related systems only when justified, approved, and constrained — never as unrestricted default remote admin.

Implementation Guidance

  1. Define which privileged roles may use remote access at all (prefer on-site or PAW for highest risk).
  2. Route privileged remote work through PAM with command filters, session recording, and MFA.
  3. Separate standard remote clinical access from privileged remote admin paths.
  4. Document business need for each privileged remote capability (on-call DBA, EHR hoster, interface engineer).
  5. Time-box vendor privileged remote; disable standing always-on admin tunnels.
  6. Prohibit privileged remote from unmanaged personal devices.
  7. Alert on privileged group use over VPN.
  8. Review privileged remote entitlements quarterly.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

On-call DBA from home

Production ePHI DB changes require PAM check-out over VPN with recording — not direct SQL from a personal laptop admin account.

EHR security admin travel

Role config changes from a conference hotel only via VDI PAW; AC-17(4) documents why remote privileged access is allowed for this job and under what device rules.

Imaging vendor kernel patch

OEM gets time-limited privileged remote through the managed gateway for a PACS host; standing root VPN is denied.

Best Practices

  • Default deny privileged remote; approve by role.
  • PAM + recording for production ePHI.
  • Managed devices only.
  • Quarterly entitlement reviews.
  • Document rationale in the remote access standard.
  • Prefer break-glass on-site for catastrophic changes when feasible.

Common Gaps & Violations

  • All Domain Admins have standing VPN with full LAN rights.
  • Vendor root tunnels never expire.
  • Privileged remote from BYOD without controls.
  • No written rationale for who may elevate remotely.
  • Helpdesk privileged tools exposed through consumer remote software.

Required Documentation

  • Privileged remote access authorization matrix (AC-17(4))
  • Rationale for each privileged remote use case
  • PAM/session recording configs
  • Vendor privileged remote procedure
  • Quarterly review evidence

How to Test & Validate

  1. Attempt privileged action over standard clinical VPN path; confirm deny or require PAM.
  2. Verify session recording for a test privileged remote.
  3. Sample Domain Admins for remote entitlement justification.
  4. Confirm vendor privileged sessions are time-boxed.
  5. Check unmanaged device cannot open privileged remote path.

Audit Considerations

Ask who can run privileged commands remotely into ePHI systems. Broad standing admin VPN without documented need fails AC-17(4).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — privileged remote functions need strict limitation.
  • 164.308(a)(3) Workforce Security — authorization/supervision for elevated remote duties.
  • 164.312(b) Audit Controls — privileged remote commands must be examinable.
  • 164.308(a)(4) Information Access Management — manage who may establish privileged access remotely.

Compliance Tips

  • Keep a one-page privileged-remote matrix for auditors.
  • Align AC-17(4) with AC-6 and AC-2(7) separate admin accounts.
  • Put privileged remote in change tickets as a risk flag.

Frequently Asked Questions

Can clinicians have privileged remote access?

Clinical charting is not privileged admin. Privileged remote means security-relevant or administrative commands — keep those rare and controlled.

Is VPN MFA enough for AC-17(4)?

MFA is necessary but not sufficient; you still need authorization limits, documentation of need, and preferably command control/recording.

Are cloud console Owner roles ‘remote privileged’?

Yes — treat cloud admin as privileged remote access with the same rigor.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(4)
  • Related controls: AC-17, AC-6, AC-2(7), AU-2, IA-2

Need Help Implementing AC-17(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.