AC-18(1) Access Control

Authentication and Encryption

High Risk Moderate Medium Cost

AC-18(1) enhances base AC-18 by protecting wireless access using authentication and encryption. Open or PSK-only clinical SSIDs that route to EHR VLANs fail this enhancement. Hospitals and clinics should use enterprise authentication (802.1X) and strong wireless encryption so only authorized devices join networks that can reach ePHI, and traffic is not trivial to intercept in waiting rooms or parking lots.

Control Objective

Require authenticated, encrypted wireless associations for any SSID that can access or transit toward systems containing ePHI.

Implementation Guidance

  1. Use WPA2-Enterprise or WPA3-Enterprise with 802.1X for clinical/corporate SSIDs; prefer certificate-based EAP where feasible.
  2. Encrypt wireless frames with strong ciphers; disable WEP/TKIP and mixed modes that downgrade security.
  3. Keep guest SSIDs isolated and encrypted at least with modern PSK; never bridge to ePHI VLANs.
  4. Authenticate biomed devices via MAB or certificates with strict ACL destinations (PACS only).
  5. Rotate any remaining PSK secrets on schedule; treat leaked PSK as a credential incident.
  6. Enforce RADIUS logging of success/fail associations.
  7. Ban open clinical SSIDs entirely.
  8. Validate phone/tablet MDM Wi-Fi profiles push enterprise settings automatically.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nursing SSO Wi-Fi

WOWs join the clinical SSID with machine certificates — AC-18(1) authentication and encryption — instead of a posted wall password.

Guest vs clinical split

Patients use encrypted guest Wi-Fi with no EHR routes; staff clinical SSID requires 802.1X.

Ultrasound on biomed SSID

Device authenticates and is encrypted on a restricted SSID allowed only to the archive — not the open ‘Staff’ PSK network.

Best Practices

  • Prefer 802.1X over shared PSK for ePHI-reachable SSIDs.
  • Disable legacy ciphers.
  • Log RADIUS authentications.
  • Isolate guest completely.
  • Certificate lifecycle for device Wi-Fi.
  • Retest after controller upgrades.

Common Gaps & Violations

  • Single PSK for all clinical devices posted at the desk.
  • WEP/WPA-TKIP still enabled.
  • Open ‘setup’ SSID left on.
  • Guest and clinical on one flat LAN despite encryption.
  • No authentication logs for wireless joins.

Required Documentation

  • Wireless authentication and encryption standard (AC-18(1))
  • SSID security mode inventory
  • RADIUS/NPS architecture
  • Cipher baseline and exception list
  • Sample association logs

How to Test & Validate

  1. Attempt join to clinical SSID without credentials/cert; confirm fail.
  2. Verify encryption mode on controller for each SSID.
  3. Confirm weak cipher suites disabled.
  4. Test guest cannot reach EHR IPs.
  5. Review RADIUS logs for clinical joins.

Audit Considerations

Floor walkers look for posted Wi-Fi passwords and open SSIDs. Enterprise auth evidence and guest isolation proofs support AC-18(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(e) Transmission Security — wireless is a transmission medium requiring protection.
  • 164.312(d) Person or Entity Authentication — authenticate wireless clients before network use.
  • 164.312(a)(1) Access Control — wireless entry must not bypass authorization to ePHI.
  • 164.308(a)(1) Risk Analysis — wireless interception and rogue join risks.

Compliance Tips

  • Prioritize replacing clinical PSK with 802.1X.
  • Include wireless crypto in annual technical evaluation.
  • Treat PSK leaks like password breaches.

Frequently Asked Questions

Is WPA2-PSK acceptable for clinical Wi-Fi?

It encrypts frames but shared secrets scale poorly and are hard to revoke. Prefer enterprise auth for SSIDs that reach ePHI; document risk if PSK is unavoidable.

Does guest Wi-Fi need 802.1X?

Not typically — isolate it and use strong modern encryption; never route it to ePHI.

How does AC-18(1) relate to AC-17(2)?

AC-18(1) secures the wireless hop; AC-17(2) encrypts remote access sessions (often beyond the LAN).

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-18(1)
  • NIST SP 800-153 WLAN guidance
  • Related controls: AC-18, SC-8, IA-2, SC-7

Need Help Implementing AC-18(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.