Nurse adds home SSID profile
Managed WOW blocks saving arbitrary SSIDs; only clinic enterprise profiles exist — AC-18(4) stops configuration drift.
AC-18(4) enhances base AC-18 by identifying and explicitly authorizing users allowed to independently configure wireless networking capabilities, and by restricting independent configuration to those users. Clinicians and staff should not freely add SSIDs, create hotspots, or weaken encryption on managed devices that access ePHI — only designated IT/telecom roles may change wireless configurations.
Prevent unauthorized users from changing wireless settings on organization-controlled devices that can reach ePHI; allow independent configuration only for approved roles.
How this control shows up in healthcare and HIPAA-covered environments.
Managed WOW blocks saving arbitrary SSIDs; only clinic enterprise profiles exist — AC-18(4) stops configuration drift.
Policy disables hosted network feature so a laptop with EHR access cannot bridge patients onto a personal hotspot.
Only network team accounts can change controller SSIDs; floor staff cannot alter AP settings from a web UI.
Show that ordinary users cannot reconfigure wireless on ePHI devices. MDM screenshots and least-privilege evidence support AC-18(4).
How this NIST control supports HIPAA Security Rule expectations.
Only if explicitly authorized and trained; otherwise provide IT on-call and pre-staged profiles.
BYOD needs app protection/conditional access; if the org does not control OS Wi-Fi, limit ePHI to containers and document residual risk.
Yes — restrict who may independently configure enterprise wireless infrastructure.
Related controls that commonly accompany AC-18(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.