AC-18 Access Control

Wireless Access

High Risk Moderate Medium Cost

AC-18 requires establishing usage restrictions and implementation guidance for wireless access, authorizing wireless access before allowing connections, and documenting/monitoring wireless activity. In medical offices this includes clinical SSIDs for workstations and VOIP, biomedical device Wi-Fi, staff BYOD networks, and public guest Wi-Fi that must never bridge into systems holding ePHI.

Control Objective

Ensure every wireless network is intentionally designed, authorized, and segmented so rogue or guest access cannot become a shortcut into clinical systems and ePHI.

Implementation Guidance

  1. Inventory all SSIDs, access points, controllers, and wireless-capable medical devices.
  2. Separate networks at minimum: clinical/corporate, biomed/IoT, staff BYOD (if allowed), and guest — with firewall rules between them.
  3. Use modern enterprise authentication (WPA2/WPA3-Enterprise with 802.1X) for clinical SSIDs; avoid shared PSK on networks that reach ePHI.
  4. Authorize new APs and SSIDs through change control; disable default SSIDs and vendor open networks.
  5. Continuously scan for rogue APs and evil-twin signals in clinical areas.
  6. Disable or tightly control wireless ad-hoc / peer-to-peer modes on clinical endpoints.
  7. Log wireless associations and failures; alert on unusual device joins to clinical SSIDs.
  8. Document guest Wi-Fi as intentionally isolated with no route to EHR VLANs (ties to AC-14 anonymous/guest use).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Guest Wi-Fi bridged to clinic LAN

A small practice put guest and staff on one consumer router. A visitor could scan for EHR servers. AC-18 remediation creates an isolated guest SSID with client isolation and no corporate routes — patient convenience without network exposure.

Wireless ultrasound on clinical SSID

A new ultrasound unit needs Wi-Fi to archive studies. AC-18 puts it on a biomed SSID with ACL allow-list only to PACS, certificate-based join where supported, and inventory tagging — not the open staff password network.

Rogue AP in a waiting room

A well-meaning employee plugs in a travel router for 'better signal.' Wireless IDS / periodic surveys detect the rogue SSID; security removes it and retrains staff under the wireless authorization policy.

Best Practices

  • Prefer 802.1X for any SSID that can reach ePHI systems.
  • Keep guest Wi-Fi fully isolated; enable client isolation.
  • Maintain an AP/SSID inventory with owners and locations.
  • Disable WPS and legacy weak ciphers.
  • Survey RF coverage and rogue APs at least annually (more often in large campuses).
  • Include wireless medical devices in change management.

Common Gaps & Violations

  • Single shared Wi-Fi password posted at the nurses' station.
  • Guest and clinical devices on the same flat network.
  • Old WEP/WPA-Personal still enabled 'for that one printer.'
  • No rogue AP detection.
  • Biomed devices joining the corporate SSID with weak default credentials.

Required Documentation

  • Wireless access policy and approved SSID list
  • Network diagrams (SSID → VLAN → firewall rules)
  • Authentication standards (802.1X, certificates, PSK exceptions)
  • Rogue detection procedure and last survey results
  • Guest network isolation evidence

How to Test & Validate

  1. Connect a test laptop to guest Wi-Fi and attempt to reach EHR/PACS IPs; confirm deny.
  2. Verify clinical SSID requires enterprise auth (not just a PSK).
  3. Confirm unknown APs are detected in a controlled rogue test (in a maintenance window).
  4. Review wireless controller configs against the approved SSID inventory.
  5. Spot-check biomed device wireless settings and destinations.

Audit Considerations

Assessors often walk the floor with a laptop. Be ready to show segmentation evidence and explain every SSID. Shared passwords for clinical Wi-Fi are a frequent finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — wireless entry must not bypass authorization to ePHI systems.
  • 164.312(e) Transmission Security — protect ePHI transmitted over wireless media.
  • 164.310(b)–(c) Workstation Use/Security — wireless workstations and mobile carts operate in open areas needing controlled connectivity.
  • 164.308(a)(1) Risk Analysis — wireless and rogue AP risks belong in the organization-wide analysis.

Compliance Tips

  • Put SSID changes through the same change board as firewall rules.
  • Require vendors to disclose wireless requirements before purchasing imaging or monitoring devices.
  • Retest guest isolation after every firewall or controller upgrade.

Frequently Asked Questions

Is WPA2-PSK enough for clinical Wi-Fi?

Shared PSK is weak for networks that reach ePHI because the secret spreads and is hard to revoke per user. Prefer 802.1X enterprise auth; document risk if a limited PSK exception is unavoidable.

Can patients use clinic Wi-Fi?

Yes on an isolated guest network with no access to clinical systems — document it under AC-18 (and related AC-14 considerations).

How does AC-18 relate to AC-17?

AC-18 is about wireless LAN access on premises (and similar RF links). AC-17 covers remote access methods such as VPN from outside the facility.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-18 Wireless Access
  • NIST SP 800-153 Guidelines for Securing Wireless Local Area Networks
  • HIPAA Security Rule §§ 164.312(a), 164.312(e), 164.310(b)–(c)
  • Related controls: AC-17, AC-19, SC-7, SC-8, SI-4, CM-8

Need Help Implementing AC-18?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.