AC-2(10) Access Control

Shared and Group Account Credential Change

High Risk Moderate Low Cost

AC-2(10) enhances base AC-2 by requiring that authenticators for shared and group accounts be changed when membership to those accounts changes. Where AC-2(9) restricts shared use, this enhancement mandates credential rotation when someone joins or leaves the sharing pool — closing the gap where a terminated clerk still knows the department password to an ePHI application.

Control Objective

Whenever shared/group account membership changes, change the shared authenticator promptly so former members lose access.

Implementation Guidance

  1. For every approved shared account exception, maintain a current membership list and owner.
  2. Trigger password/secret rotation on member add/remove, termination, or role change.
  3. Prefer vaulted secrets with check-out over tribal knowledge of passwords.
  4. Automate rotation where possible (PAM API, vault dynamic secrets).
  5. Include shared medical-device and appliance passwords in scope when humans share them.
  6. Document emergency rotation after suspected disclosure.
  7. Pair with AC-2(9) reduction goals — fewer shared accounts means fewer rotations.
  8. Evidence each rotation with ticket and vault history.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Night clerk leaves the ED desk pool

Shared tracking-board exception still exists during SSO rollout. When the clerk resigns, AC-2(10) rotates the shared password the same day — not at the quarterly audit.

Vendor tech rotated off contract

Three OEM engineers knew a shared support password. Membership change triggers vault rotation before the next remote session.

HIM temp ends assignment

Temporary ROI staff knew a shared scanner/export utility password. End of assignment rotates credentials and re-issues only to remaining members.

Best Practices

  • Vault all shared secrets; never email new passwords.
  • Rotation SLA measured in hours after membership change.
  • Owner accountable for membership accuracy.
  • Eliminate shared accounts where feasible.
  • Audit vault history quarterly.
  • Include contractors in membership lists.

Common Gaps & Violations

  • Shared passwords unchanged for years.
  • Terminated staff still know department EHR generic password.
  • Membership list informal and incomplete.
  • New password sent via group text.
  • Focus only on AD; ignore device/share passwords.

Required Documentation

  • Shared credential change procedure (AC-2(10))
  • Membership lists per shared account
  • Rotation SLA and vault evidence samples
  • Linkage to joiner/mover/leaver process
  • Exception inventory from AC-2(9)

How to Test & Validate

  1. Remove a test member; confirm credential changed.
  2. Verify former member cannot authenticate with old secret.
  3. Sample shared accounts for recent rotation evidence.
  4. Check vault access logs for retrieval after changes.
  5. Confirm termination checklist includes shared-secret rotation tasks.

Audit Considerations

If shared accounts exist, assessors will ask when the password last changed relative to staff turnover. AC-2(10) requires that linkage — not annual arbitrary resets alone.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(C) Termination Procedures — former workforce must lose access, including shared credentials they knew.
  • 164.312(d) Person or Entity Authentication — authenticators must remain under authorized control.
  • 164.312(a)(2)(i) Unique User Identification — shared accounts already weaken uniqueness; stale shared secrets compound the failure.
  • 164.308(a)(4) Information Access Management — access changes when workforce membership changes.

Compliance Tips

  • Add 'rotate shared secrets' as a mandatory termination sub-task when exceptions exist.
  • Reduce AC-2(9) exceptions to shrink AC-2(10) operational burden.
  • Use PAM one-time passwords for unavoidable shared break-glass.

Frequently Asked Questions

Do we still need AC-2(10) if we forbid shared accounts?

If truly zero shared interactive accounts, document that AC-2(10) is not applicable; keep the control ready for device/exception cases.

Is quarterly password change enough?

Not by itself — rotation must occur when membership changes, which may be far more frequent.

What about passphrase knowledge in a team?

Treat any human-shared authenticator as in scope; vault and rotate on membership change.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(10)
  • Related controls: AC-2, AC-2(9), IA-5, PS-4, PS-5

Need Help Implementing AC-2(10)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.