AC-19(2) Access Control

Sanitization of Information

High Risk Moderate Low Cost

AC-19(2) addresses sanitization of information from mobile devices before reassignment, disposal, repair, or after authorized use ends. Healthcare fleets recycle tablets between units, send phones for warranty repair, and collect devices at termination — without sanitization, prior patients’ messages, downloads, and cached charts can follow the hardware. Combine remote wipe, selective wipe, and media sanitization procedures aligned with MP-6.

Control Objective

Remove or render unrecoverable ePHI on mobile devices when custody changes, devices are lost, repaired, or retired.

Implementation Guidance

  1. Define sanitization triggers: termination, transfer, repair, surplus, lost/stolen, BYOD offboarding.
  2. Use MDM full wipe for corporate devices; selective wipe for BYOD containers.
  3. Verify wipe completion; escalate if device offline (encryption + legal hold process).
  4. Before vendor repair, wipe or remove storage per policy; never ship live ePHI caches.
  5. Reassign clinical tablets only after certified wipe and re-enrollment.
  6. Document chain of custody for devices with ePHI.
  7. Align methods with NIST SP 800-88 media sanitization guidance.
  8. Train workforce on immediate lost-device reporting to enable wipe.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Provider leaves the medical group

Corporate phone is fully wiped the same day HR terminates; clinical apps and mail caches are sanitized under AC-19(2).

Tablet moves from oncology to pediatrics

Device is wiped and re-enrolled so oncology patient lists do not remain in local storage.

Warranty repair laptop

SSD is sanitized or retained; loaner issued — vendor never receives a drive with readable ePHI.

Best Practices

  • Wipe before repair/surplus.
  • Selective wipe for BYOD offboarding.
  • Verify wipe success in MDM.
  • Pair with encryption (defense in depth).
  • Keep sanitization certificates for disposed media.
  • Fast lost-device SLA.

Common Gaps & Violations

  • Reassigning tablets without wipe.
  • Shipping devices to vendors with live email profiles.
  • No wipe on voluntary BYOD exit.
  • Assuming factory reset without MDM confirmation.
  • Lost device reported days later with no interim action.

Required Documentation

  • Mobile sanitization procedure (AC-19(2))
  • Wipe types by device ownership (corporate/BYOD)
  • Lost/stolen wipe playbook
  • Surplus/repair chain-of-custody forms
  • MDM wipe evidence samples

How to Test & Validate

  1. Execute test selective wipe on BYOD profile; confirm work data gone.
  2. Full-wipe a corporate test device; verify enrollment state.
  3. Review recent terminations for wipe timestamps.
  4. Inspect repair/surplus tickets for sanitization steps.
  5. Confirm offline lost-device process (encryption + watch listing).

Audit Considerations

Device and media control auditors sample surplus and terminated-user devices. Missing wipe evidence for mobile ePHI endpoints is a frequent finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d)(2)(i) Disposal — policies for disposal of ePHI and/or hardware/media.
  • 164.310(d)(2)(ii) Media Re-use — sanitize before re-use.
  • 164.312(a)(2)(iv) Encryption — complements sanitization when wipe is delayed.
  • 164.308(a)(3)(ii)(C) Termination Procedures — collect/sanitize devices at exit.

Compliance Tips

  • Put device wipe on the same checklist as account disable.
  • Offer self-service ‘retire my BYOD’ that triggers selective wipe.
  • Keep 800-88 method mapping in the media sanitization standard.

Frequently Asked Questions

Is remote wipe always possible?

Not if the device is offline or wipe is blocked — encryption and rapid reporting reduce residual risk; document the process.

Does factory reset equal sanitization?

It may for some flash devices if done correctly, but prefer MDM-verified wipe and follow 800-88 for storage removed from devices.

How is this different from MP-6?

MP-6 is the general media sanitization control; AC-19(2) emphasizes sanitization in the mobile-device access-control context.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-19 family / MP-6
  • NIST SP 800-88 Guidelines for Media Sanitization
  • Related controls: AC-19, MP-6, MP-5, IR-4, PS-4

Need Help Implementing AC-19(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.