AC-19 Access Control

Access Control for Mobile Devices

High Risk Moderate Medium Cost

AC-19 requires establishing usage restrictions and implementation guidance for organization-controlled mobile devices, and authorizing connection of mobile devices before they can access organizational systems. Phones, tablets, and laptops used for EHR apps, secure messaging, dictation, or VPN are high-loss, high-theft assets — AC-19 makes sure they meet encryption, authentication, and management bars before touching ePHI.

Control Objective

Prevent unmanaged or weakly protected mobile devices from becoming an easy exfiltration or loss path for ePHI, while still supporting clinicians who work on the move.

Implementation Guidance

  1. Define mobile categories: corporate-owned, BYOD, and kiosk/shared clinical tablets — with rules for each.
  2. Require MDM/EMM enrollment (or equivalent app protection policies) before access to email, EHR apps, or VPN containing ePHI.
  3. Enforce device encryption, screen lock, OS minimum version, and remote wipe / selective wipe.
  4. Prefer app containers or secure browsers so personal BYOD data stays separate from corporate ePHI.
  5. Prohibit local download of ePHI to unmanaged personal storage (photos, consumer cloud) unless a managed path exists.
  6. Authorize devices via inventory: only enrolled devices get certificates or conditional access.
  7. Train workforce on lost-device reporting SLAs (minutes matter for wipe).
  8. Include loaner tablets and provider personal phones used for on-call — not only IT-issued laptops.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Lost on-call phone with Secure Chat

A hospitalist's phone with a clinical messaging app is left in a rideshare. Because AC-19 required MDM and selective wipe, IT removes the work container within minutes; personal photos remain, ePHI does not.

BYOD tablet for rounding

Physicians want EHR on personal iPads. Conditional access allows the EHR app only when the device is encrypted, PIN-locked, OS-current, and covered by app protection — blocking jailbroken or ancient iOS versions.

Shared ED trauma tablet

An emergency department shared tablet is enrolled as a supervised device with single-app or limited-app mode, auto-lock, and no consumer app store — reducing misconfiguration risk compared with unmanaged consumer tablets.

Best Practices

  • Use conditional access: no enrollment, no ePHI apps.
  • Prefer selective wipe for BYOD to improve adoption.
  • Maintain a mobile device inventory tied to users.
  • Block USB/file-sync paths that dump charts to personal clouds.
  • Test wipe procedures quarterly.
  • Align mobile policy with AC-17 remote access and MP media protection.

Common Gaps & Violations

  • ActiveSync email with ePHI on phones that have no PIN or encryption requirement.
  • Clinicians photographing whiteboards/wounds to personal camera rolls.
  • No wipe capability for BYOD.
  • Shared tablets using a single personal Apple ID.
  • MDM installed but compliance policies not enforced (report-only forever).

Required Documentation

  • Mobile device / BYOD policy
  • MDM configuration baselines and compliance rules
  • Device authorization / enrollment procedure
  • Lost/stolen device incident playbook
  • Inventory of corporate and enrolled BYOD devices accessing ePHI

How to Test & Validate

  1. Attempt EHR/email access from an unenrolled device; confirm block.
  2. Verify encryption and PIN enforcement on a sample of enrolled devices.
  3. Execute a test selective wipe on a non-production BYOD profile.
  4. Confirm jailbreak/root or outdated OS is marked non-compliant.
  5. Review lost-device tickets for wipe timestamps vs report times.

Audit Considerations

Auditors sample phones/tablets and ask how ePHI apps are controlled. 'We have MDM' without enforced compliance policies is insufficient. Show conditional access and wipe evidence.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — mobile endpoints are systems that must limit ePHI access to authorized users.
  • 164.312(a)(2)(iv) Encryption and Decryption — addressable encryption is commonly implemented on mobile devices storing ePHI.
  • 164.310(d) Device and Media Controls — mobile devices are electronic media requiring receipt, removal, and disposal controls.
  • 164.308(a)(1) Risk Analysis — loss/theft of mobile devices is a classic risk requiring AC-19-style treatments.

Compliance Tips

  • Start enforcement with email and EHR apps — highest ePHI concentration.
  • Offer a corporate loaner pool so BYOD holdouts still have a compliant option.
  • Include mobile device checks in new-hire IT onboarding day one.

Frequently Asked Questions

Does AC-19 ban BYOD?

No. It requires usage restrictions and authorization. BYOD can work with app protection / MDM and clear ePHI handling rules.

Are laptops 'mobile devices' under AC-19?

Portable computing devices are in scope of the mobile device family of controls; apply laptop encryption, inventory, and remote wipe/lock consistently.

How fast should we wipe a lost phone?

As soon as the loss is reported and identity is verified — measure in minutes when ePHI apps were installed. Document the SLA in your IR procedures.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-19 Access Control for Mobile Devices
  • NIST SP 800-124 Guidelines for Managing the Security of Mobile Devices
  • HIPAA Security Rule §§ 164.312(a), 164.310(d)
  • Related controls: AC-17, AC-18, MP-5, MP-6, IA-2, SI-2

Need Help Implementing AC-19?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.