AC-18(3) Access Control

Disable Wireless Networking

Medium Risk Easy Low Cost

AC-18(3) enhances base AC-18 by disabling wireless networking when unused as an organizational capability interface. EHR database servers, PACS archives, interface engines, and wired nursing kiosks that never need Wi-Fi should have radios disabled in firmware/OS/BIOS so they cannot join rogue SSIDs or bridge clinical networks unintentionally.

Control Objective

Disable wireless interfaces on systems that process or store ePHI when wireless is not required for the business function.

Implementation Guidance

  1. Inventory which ePHI systems have Wi-Fi/Bluetooth hardware.
  2. Disable radios via BIOS/UEFI, OS policy, and driver where wireless is unnecessary.
  3. Prefer wired-only builds for servers, VDI hosts, and fixed clinical workstations.
  4. MDM/GPO: disallow enabling Wi-Fi for roles that are wired-only.
  5. Cover Bluetooth as a wireless networking vector for proximity exfil where policy requires.
  6. Exception process for true mobile clinical devices.
  7. Verify after imaging/reimaging that radios stay disabled.
  8. Include disable checks in hardening baselines (CM-2/CM-6).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Charting PC next to MRI control

Fixed workstation is Ethernet-only; Wi-Fi disabled so it cannot soft-AP or join guest networks with ePHI open.

Virtualization host

Hypervisor hardware had Wi-Fi NICs for ‘convenience’; AC-18(3) disables them in firmware as part of the ePHI host baseline.

Admission kiosk

Touchscreen check-in device on wired LAN with radio off prevents patients’ phones from pairing unexpectedly.

Best Practices

  • Default disable on servers and fixed endpoints.
  • Enforce via BIOS password + OS policy.
  • Re-verify after OS redeploy.
  • Document mobile exceptions.
  • Include Bluetooth in scope when risk warrants.
  • Pair with AC-18(4) user config restrictions.

Common Gaps & Violations

  • Servers leave Wi-Fi on by default.
  • Users re-enable radios without approval.
  • Imaging process omits wireless disable step.
  • Only OS disable — BIOS still active and user toggles it.
  • Ignoring Bluetooth on clinical laptops in exam rooms.

Required Documentation

  • Wireless disable standard (AC-18(3))
  • Hardening baseline for wired-only ePHI systems
  • Inventory of systems with radios disabled vs excepted
  • MDM/GPO settings evidence
  • Exception approvals for mobile devices

How to Test & Validate

  1. Sample ePHI servers/workstations; confirm Wi-Fi disabled.
  2. Attempt to enable Wi-Fi as standard user; expect block.
  3. Redeploy a gold image; re-check radio state.
  4. Review exception list against actual mobile fleet.
  5. Spot-check BIOS wireless settings on server builds.

Audit Considerations

Ask whether servers holding ePHI can join Wi-Fi. Disabled radios on non-mobile systems are simple, high-value AC-18(3) evidence.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis — unnecessary wireless interfaces increase attack surface.
  • 164.312(a)(1) Access Control — reduce unintended network access paths.
  • 164.310(c) Workstation Security — harden workstations against misuse.
  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — fewer radios reduce some worm/bridge scenarios.

Compliance Tips

  • Add ‘wireless disabled’ to the server build checklist.
  • Treat re-enabled radios on wired clinical PCs as configuration drift incidents.
  • Coordinate with clinical engineering for biomed wired-only devices.

Frequently Asked Questions

Must every laptop disable Wi-Fi?

No — mobile devices need wireless. AC-18(3) targets systems where wireless is unused.

Is airplane mode enough?

Prefer policy-enforced disable that users cannot casually reverse on wired-only assets.

Does this include Bluetooth?

Many programs include Bluetooth under wireless networking restrictions for ePHI endpoints — define scope in policy.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-18(3)
  • Related controls: AC-18, AC-18(4), CM-7, CM-2, SC-7

Need Help Implementing AC-18(3)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.