Night clerk leaves the ED desk pool
Shared tracking-board exception still exists during SSO rollout. When the clerk resigns, AC-2(10) rotates the shared password the same day — not at the quarterly audit.
AC-2(10) enhances base AC-2 by requiring that authenticators for shared and group accounts be changed when membership to those accounts changes. Where AC-2(9) restricts shared use, this enhancement mandates credential rotation when someone joins or leaves the sharing pool — closing the gap where a terminated clerk still knows the department password to an ePHI application.
Whenever shared/group account membership changes, change the shared authenticator promptly so former members lose access.
How this control shows up in healthcare and HIPAA-covered environments.
Shared tracking-board exception still exists during SSO rollout. When the clerk resigns, AC-2(10) rotates the shared password the same day — not at the quarterly audit.
Three OEM engineers knew a shared support password. Membership change triggers vault rotation before the next remote session.
Temporary ROI staff knew a shared scanner/export utility password. End of assignment rotates credentials and re-issues only to remaining members.
If shared accounts exist, assessors will ask when the password last changed relative to staff turnover. AC-2(10) requires that linkage — not annual arbitrary resets alone.
How this NIST control supports HIPAA Security Rule expectations.
If truly zero shared interactive accounts, document that AC-2(10) is not applicable; keep the control ready for device/exception cases.
Not by itself — rotation must occur when membership changes, which may be far more frequent.
Treat any human-shared authenticator as in scope; vault and rotate on membership change.
Related controls that commonly accompany AC-2(10).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.