AC-18(2) Access Control

Monitoring Unauthorized Connections

High Risk Moderate Medium Cost

AC-18(2) enhances base AC-18 by monitoring for unauthorized wireless connections to organizational systems. Rogue access points in waiting rooms, evil-twin SSIDs mimicking the clinic name, and unsanctioned bridges from clinical devices create silent paths toward ePHI. Continuous or frequent wireless monitoring detects these before credentials or charts are intercepted.

Control Objective

Detect and respond to unauthorized wireless connections and rogue RF infrastructure that could expose or bypass controls protecting ePHI.

Implementation Guidance

  1. Enable WIPS/WIDS or controller-based rogue detection across clinical campuses.
  2. Alert on rogue APs, ad-hoc networks, and spoofed SSID names.
  3. Inventory authorized APs; alarm on unknown BSSIDs in care areas.
  4. Monitor for authorized endpoints associating to unknown SSIDs (mis-association).
  5. Include periodic manual RF surveys for areas without full WIPS coverage.
  6. Define response: locate, contain, remove, and educate for employee travel routers.
  7. Watch biomed devices for unexpected wireless destinations.
  8. Retain wireless security events for audit and IR correlation.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Evil twin ‘ClinicGuest’

Attacker broadcasts a lookalike SSID outside the building. AC-18(2) detection and staff awareness reduce credential capture risk for users who might have clinical VPN profiles.

Travel router at nursing station

Employee plugs in a personal AP. WIPS flags the rogue; security removes it under wireless policy.

Mis-associated WOW

A workstation joins a neighboring office’s weak SSID. Monitoring detects the unauthorized connection path away from managed clinical Wi-Fi.

Best Practices

  • Continuous WIPS where patient care density is high.
  • Keep authorized AP inventory current.
  • Respond to rogues within defined SLAs.
  • Train staff not to create personal APs.
  • Survey after construction/moves.
  • Correlate with SI-4 network monitoring.

Common Gaps & Violations

  • No rogue detection at all.
  • Alerts enabled but never triaged.
  • Annual survey only on a multi-building campus.
  • Authorized AP list outdated after renovations.
  • Ignoring ad-hoc/hotspot soft APs from phones.

Required Documentation

  • Unauthorized wireless monitoring procedure (AC-18(2))
  • WIPS/WIDS configuration and coverage map
  • Authorized AP inventory
  • Rogue response runbook
  • Sample alerts and closures

How to Test & Validate

  1. Controlled rogue AP test in maintenance window; confirm detect/alert.
  2. Verify authorized inventory matches controller APs.
  3. Review 30–90 days of rogue alerts for disposition.
  4. Confirm mis-association alerts for test client.
  5. Validate coverage gaps have compensating survey schedule.

Audit Considerations

Assessors ask how you know there is no rogue Wi-Fi in clinical areas. WIPS evidence and recent survey reports demonstrate AC-18(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1)(ii)(D) Information System Activity Review — include wireless security events.
  • 164.312(b) Audit Controls — record wireless association and rogue events where feasible.
  • 164.312(a)(1) Access Control — unauthorized wireless can bypass intended access paths.
  • 164.308(a)(6) Security Incident Procedures — rogue AP is an incident class.

Compliance Tips

  • Put rogue-AP response on the security on-call card.
  • Re-survey after clinic remodels.
  • Include affiliated offices in monitoring scope or document residual risk.

Frequently Asked Questions

Is an annual wireless survey enough?

For small single-floor clinics maybe with risk acceptance; larger campuses generally need continuous WIPS plus periodic surveys.

Are phone hotspots in scope?

Yes when they create unauthorized wireless networks in clinical areas or lure managed devices.

How does this differ from AC-17(5)?

AC-18(2) focuses on wireless unauthorized connections; AC-17(5)/SI-4 covers broader unauthorized remote connections.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-18(2)
  • Related controls: AC-18, SI-4, CM-8, IR-4, PE-3

Need Help Implementing AC-18(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.