AC-17(9) Access Control

Disconnect or Disable Access

High Risk Moderate Medium Cost

AC-17(9) enhances base AC-17 by providing the capability to disconnect or disable remote access to the system within an organization-defined time period. Healthcare needs rapid cutoff when sessions idle too long, when accounts are terminated, during ransomware response, or when anomalous remote behavior threatens ePHI — not waiting for the user to log off voluntarily.

Control Objective

Disconnect or disable remote access to ePHI-capable systems quickly under defined conditions (idle limits, security events, authorization loss).

Implementation Guidance

  1. Define disconnect conditions: idle timeout, max session length, account disable, IR declare, failed posture check.
  2. Configure VPN/VDI/ZTNA to enforce idle and absolute timeouts aligned with risk.
  3. Ensure IdP disable propagates to active remote sessions (session revoke), not only future logons.
  4. Empower SOC to kill remote sessions during incidents within minutes.
  5. Auto-disable vendor remote access at ticket end time.
  6. Re-evaluate posture continuously; disconnect non-compliant devices.
  7. Test termination for cloud EHR sessions (revoke refresh tokens).
  8. Document after-hours authorities who can order mass remote disconnect.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Ransomware containment

IR lead orders AC-17(9) mass VPN disconnect while preserving break-glass on-site admin paths — stops remote lateral movement toward EHR.

Idle home VDI

Coder’s VDI idles past policy; broker disconnects so household members cannot walk up to an open ePHI desktop.

Terminated remote nurse

Account disabled; active telehealth/EHR tokens revoked so the session dies before the next chart open.

Best Practices

  • Idle + absolute session limits.
  • Real-time revoke on disable.
  • Practiced mass-disconnect runbook.
  • Vendor auto-expire.
  • Continuous compliance checks.
  • Measure time-to-disconnect KPIs.

Common Gaps & Violations

  • VPN sessions lasting days with no idle limit.
  • Disable user in AD but refresh tokens keep cloud EHR open.
  • No SOC capability to kill sessions.
  • Vendor tunnels only closed when someone remembers.
  • Timeouts documented but not enforced on all remote methods.

Required Documentation

  • Remote disconnect/disable standard (AC-17(9))
  • Timeout matrix by remote method
  • IR mass-disconnect runbook
  • Token revocation procedure for cloud ePHI apps
  • Test records for session kill

How to Test & Validate

  1. Idle a VPN/VDI session past limit; confirm disconnect.
  2. Disable a test account; confirm live remote session ends.
  3. Execute test session kill from SOC tools.
  4. Verify vendor access auto-disables at end time.
  5. Confirm cloud EHR token revoke behavior.

Audit Considerations

Compare termination or incident timestamps to remote session end times. Lingering remote access after disable is a serious HIPAA access-control finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(C) Termination Procedures — end access when employment ends, including remote.
  • 164.312(a)(2)(iii) Automatic Logoff — inactivity disconnect supports this specification.
  • 164.312(a)(1) Access Control — ability to remove remote access promptly.
  • 164.308(a)(6) Security Incident Procedures — disconnect is a containment action.

Compliance Tips

  • Put remote session revoke on the termination checklist with evidence fields.
  • Align timeouts with AC-2(5)/AC-12.
  • Practice mass VPN kill in annual IR exercises.

Frequently Asked Questions

Does idle timeout alone satisfy AC-17(9)?

It is one condition. Also cover security events, max duration, and authorization loss with real disconnect capability.

How fast is fast enough?

Define SLAs by risk — privileged and incident-driven disconnects often measured in minutes.

What about offline cached credentials?

Address device-level caches and VPN always-on profiles so disable remains effective.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(9)
  • Related controls: AC-17, AC-12, AC-2(5), IR-4, SI-4

Need Help Implementing AC-17(9)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.