Ransomware containment
IR lead orders AC-17(9) mass VPN disconnect while preserving break-glass on-site admin paths — stops remote lateral movement toward EHR.
AC-17(9) enhances base AC-17 by providing the capability to disconnect or disable remote access to the system within an organization-defined time period. Healthcare needs rapid cutoff when sessions idle too long, when accounts are terminated, during ransomware response, or when anomalous remote behavior threatens ePHI — not waiting for the user to log off voluntarily.
Disconnect or disable remote access to ePHI-capable systems quickly under defined conditions (idle limits, security events, authorization loss).
How this control shows up in healthcare and HIPAA-covered environments.
IR lead orders AC-17(9) mass VPN disconnect while preserving break-glass on-site admin paths — stops remote lateral movement toward EHR.
Coder’s VDI idles past policy; broker disconnects so household members cannot walk up to an open ePHI desktop.
Account disabled; active telehealth/EHR tokens revoked so the session dies before the next chart open.
Compare termination or incident timestamps to remote session end times. Lingering remote access after disable is a serious HIPAA access-control finding.
How this NIST control supports HIPAA Security Rule expectations.
It is one condition. Also cover security events, max duration, and authorization loss with real disconnect capability.
Define SLAs by risk — privileged and incident-driven disconnects often measured in minutes.
Address device-level caches and VPN always-on profiles so disable remains effective.
Related controls that commonly accompany AC-17(9).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.