AC-18(4) Access Control

Restrict Configurations by Users

Medium Risk Moderate Low Cost

AC-18(4) enhances base AC-18 by identifying and explicitly authorizing users allowed to independently configure wireless networking capabilities, and by restricting independent configuration to those users. Clinicians and staff should not freely add SSIDs, create hotspots, or weaken encryption on managed devices that access ePHI — only designated IT/telecom roles may change wireless configurations.

Control Objective

Prevent unauthorized users from changing wireless settings on organization-controlled devices that can reach ePHI; allow independent configuration only for approved roles.

Implementation Guidance

  1. Lock Wi-Fi settings via MDM/GPO on corporate clinical laptops, WOWs, and shared tablets.
  2. Push approved SSIDs only; block user-added networks where feasible.
  3. Disable user ability to create hosted networks/hotspots/soft APs.
  4. Restrict Bluetooth pairing policies for clinical devices as needed.
  5. Authorize a small admin group for wireless troubleshooting and controller changes.
  6. Log configuration changes on controllers and endpoints.
  7. Train that ‘fixing Wi-Fi’ is an IT function, not a bedside DIY task.
  8. Review local admin rights that bypass wireless restrictions.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nurse adds home SSID profile

Managed WOW blocks saving arbitrary SSIDs; only clinic enterprise profiles exist — AC-18(4) stops configuration drift.

Soft AP from clinician laptop

Policy disables hosted network feature so a laptop with EHR access cannot bridge patients onto a personal hotspot.

Helpdesk wireless admins

Only network team accounts can change controller SSIDs; floor staff cannot alter AP settings from a web UI.

Best Practices

  • MDM-enforced Wi-Fi profiles.
  • Remove local admin on clinical endpoints.
  • Disable hotspot/soft-AP features.
  • Narrow who can change controller configs.
  • Audit wireless setting changes.
  • Pair with AC-18(3) for wired-only devices.

Common Gaps & Violations

  • Users are local admins and change Wi-Fi freely.
  • BYOD unmanaged yet fully accessing ePHI apps.
  • Hotspot features enabled on clinical laptops.
  • Shared controller admin password at the desk.
  • No list of who may configure wireless independently.

Required Documentation

  • Wireless configuration authority standard (AC-18(4))
  • MDM/GPO restriction settings
  • Authorized wireless administrator roles
  • Change-control process for SSID/controller edits
  • Exception handling for specialty devices

How to Test & Validate

  1. As standard clinical user, attempt to add SSID or enable hotspot; confirm deny.
  2. Confirm approved profiles still connect.
  3. Verify only authorized admins can change controller settings.
  4. Sample endpoints for local admin bypass risk.
  5. Review wireless config change logs.

Audit Considerations

Show that ordinary users cannot reconfigure wireless on ePHI devices. MDM screenshots and least-privilege evidence support AC-18(4).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — limit who can alter security-relevant configurations.
  • 164.312(a)(1) Access Control — configuration control supports effective access enforcement.
  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — uncontrolled wireless changes increase malware/bridge risk.
  • 164.310(b) Workstation Use — proper use includes not altering network safeguards.

Compliance Tips

  • Remove local admin as the primary enabler of AC-18(4) failures.
  • Include wireless config locks in the endpoint security baseline.
  • Authorize clinical engineering separately for biomed wireless only within ACM process.

Frequently Asked Questions

Can power users configure Wi-Fi for downtime?

Only if explicitly authorized and trained; otherwise provide IT on-call and pre-staged profiles.

Does BYOD conflict with AC-18(4)?

BYOD needs app protection/conditional access; if the org does not control OS Wi-Fi, limit ePHI to containers and document residual risk.

Are controller changes in scope?

Yes — restrict who may independently configure enterprise wireless infrastructure.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-18(4)
  • Related controls: AC-18, AC-18(3), CM-5, AC-6, CM-7

Need Help Implementing AC-18(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.