Rogue remote agent on clinic PC
EDR finds an unapproved remote-support install calling home. Treated as SI-4/AC-17 unauthorized remote path; host isolated before ePHI access.
AC-17(5) historically required monitoring for unauthorized remote connections to the system. In NIST SP 800-53 Rev. 5 this enhancement is withdrawn and incorporated into SI-4 (System Monitoring). Healthcare programs should still detect rogue VPN concentrators, unexpected inbound remote ports, unauthorized remote-support agents, and unapproved cloud admin paths that could reach ePHI — implementing that capability under SI-4 while preserving AC-17 remote-access policy context.
Detect unauthorized remote connection methods and attempts involving ePHI environments, recognizing Rev. 5 maps this outcome primarily to SI-4 while operational need remains.
How this control shows up in healthcare and HIPAA-covered environments.
EDR finds an unapproved remote-support install calling home. Treated as SI-4/AC-17 unauthorized remote path; host isolated before ePHI access.
External scan finds RDP open on a forgotten imaging PC. Monitoring and edge controls close the unauthorized remote connection path.
A department spins up a personal reverse tunnel into a billing share. Firewall anomalies flag it as unauthorized remote connectivity.
If an assessor still cites AC-17(5), show Rev. 5 withdrawal into SI-4 plus living detections for unauthorized remote paths to ePHI — not a blank N/A.
How this NIST control supports HIPAA Security Rule expectations.
It is withdrawn/incorporated into SI-4. Implement the capability under SI-4 and note the mapping.
Assessors, older SSPs, and contracts may still reference AC-17(5); operational risk of unauthorized remote access did not disappear.
AC-17(1) monitors/controls authorized remote methods; unauthorized connection detection is broader and lives primarily in SI-4.
Related controls that commonly accompany AC-17(5).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.