Same-day nurse termination
Night-shift RN is terminated at 14:00. AC-2(1) HRIS event disables IdP; SCIM revokes EHR and VPN within the SLA — base AC-2 policy alone would still wait on a helpdesk ticket.
AC-2(1) enhances base AC-2 by requiring the organization to support the management of system accounts using automated mechanisms. Base AC-2 defines the lifecycle (create, enable, modify, disable, remove, monitor); this enhancement insists that core steps are driven by automation — typically HRIS-to-IdP connectors, SCIM, or workflow bots — so ePHI access does not depend on ad-hoc tickets that sit in queues after terminations or transfers.
Automate account create/modify/disable/remove for systems that handle ePHI so access changes track workforce events in near real time and leave an auditable trail.
How this control shows up in healthcare and HIPAA-covered environments.
Night-shift RN is terminated at 14:00. AC-2(1) HRIS event disables IdP; SCIM revokes EHR and VPN within the SLA — base AC-2 policy alone would still wait on a helpdesk ticket.
A MA moves from Clinic A to Clinic B. Automation removes Clinic A location roles and assigns Clinic B packs overnight, preventing dual-site chart access that manual movers often leave behind.
Fifty nursing students start Monday. Automated bulk joiner jobs create time-limited accounts tied to the semester end date, rather than fifty one-off EHR admin creates.
Assessors distinguish paper JML from automated enforcement. Show event logs proving disable followed the HR timestamp — not a ticket closed days later.
How this NIST control supports HIPAA Security Rule expectations.
No. Base AC-2 still defines account types, managers, and reviews; AC-2(1) requires automation to support that lifecycle.
Prioritize systems with ePHI. Document compensating manual controls and timelines for residual apps.
Prefer near-real-time for terminations. Nightly may be acceptable for low-risk creates if risk analysis supports it — document the decision.
Related controls that commonly accompany AC-2(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.