AC-17(6) Access Control

Protection of Mechanism Information

Medium Risk Easy Low Cost

AC-17(6) enhances base AC-17 by protecting information about remote access mechanisms from unauthorized disclosure. Publishing VPN hostnames on public websites, leaving default portal banners with internal topology, or sharing gateway credentials in unprotected tickets helps adversaries target healthcare remote entry points that lead to ePHI.

Control Objective

Limit who can learn how remote access to ePHI environments works — endpoints, URLs, protocols, and configuration details — to authorized personnel and documented channels.

Implementation Guidance

  1. Avoid posting VPN/VDI URLs and connection guides on public internet pages; use authenticated intranet or MDM-managed profiles.
  2. Minimize verbose error banners and realm names on remote portals that reveal internal naming.
  3. Restrict network diagrams of remote gateways to need-to-know repositories.
  4. Do not place gateway passwords or shared secrets in cleartext tickets or chat.
  5. Control DNS and certificate SANs disclosure where feasible; monitor for credential-stuffing on known portals.
  6. Train helpdesk on what remote-access details may be given over unauthenticated phone calls.
  7. Sanitize screenshots in public RFPs that show remote architecture.
  8. Review third-party status pages and BA portals for over-sharing of connection methods.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

VPN URL on marketing site

‘Connect from home’ public page listed the exact VPN FQDN and realm. AC-17(6) moves instructions behind SSO intranet and MDM auto-config.

Over-verbose portal banner

SSL VPN showed ‘Hospital Clinical VLAN Gateway – AD.CORP.’ Hardened banner reduces mechanism fingerprinting.

Vendor email with connection kit

Unencrypted email contained jump-host IPs and temporary passwords. Process shifts to time-limited PAM invites without topology dumps.

Best Practices

  • Authenticated distribution of remote client configs.
  • Minimal public portal banners.
  • Secrets only in vaults.
  • Need-to-know for architecture diagrams.
  • Verify helpdesk identity before sharing remote details.
  • Review public web for leaked VPN hostnames.

Common Gaps & Violations

  • Public wiki with full remote access runbooks.
  • Shared VPN PSK posted in Slack #general.
  • RFP appendices with detailed remote network maps.
  • Default vendor portal pages exposing product and realm.
  • Printed ‘how to VPN’ cards left in waiting areas.

Required Documentation

  • Remote access information protection standard (AC-17(6))
  • Approved channels for distributing connection instructions
  • Portal banner / information disclosure baseline
  • Secret handling for gateway credentials
  • Periodic public-web leak checks

How to Test & Validate

  1. Search public web/code repos for VPN hostnames and remote guides.
  2. Browse remote portals as anonymous user; note information disclosed.
  3. Sample tickets for remote secrets in cleartext.
  4. Confirm MDM delivers profiles without public download pages.
  5. Review BA-facing docs for over-sharing.

Audit Considerations

Assessors may simply Google your VPN hostname. Public connection kits and verbose portals are soft targets that undermine otherwise strong AC-17 crypto and MFA.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis — reconnaissance of remote entry points is a known threat.
  • 164.312(a)(1) Access Control — protecting mechanism details supports effective access control.
  • 164.308(a)(4) Information Access Management — limit knowledge of how access is obtained.
  • 164.530(c) Safeguards — reasonable administrative safeguards include not advertising access paths.

Compliance Tips

  • Prefer silent MDM VPN profiles over DIY user setup guides on the open web.
  • Add ‘remote mechanism disclosure’ to the data classification scheme.
  • Red-team recon notes should feed AC-17(6) fixes.

Frequently Asked Questions

Must VPN hostnames be secret forever?

Absolute secrecy is unrealistic; the goal is not to advertise and not to leak configs/credentials. Defense in depth still requires MFA and monitoring.

Can employees share the VPN URL internally?

Yes via approved authenticated channels. Avoid public posts and unauthenticated distribution.

Does this apply to patient portal URLs?

Patient portals are intentionally public endpoints — still minimize banner leakage and protect admin remote mechanisms separately.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(6)
  • Related controls: AC-17, AC-3, SC-5, SI-4, IA-5

Need Help Implementing AC-17(6)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.