Celebrity admission snooping
Multiple accounts open a VIP chart without care relationship. AC-2(12) atypical access alerts hit privacy within minutes for sanctions review — beyond waiting for a complaint.
AC-2(12) enhances base AC-2 by monitoring accounts for atypical usage and reporting atypical usage to organization-defined personnel or roles. Base AC-2 includes monitoring account use at a general level; this enhancement requires detecting anomalous patterns — VIP chart access spikes, off-hours bulk lookups, impossible travel — that often signal insider curiosity or compromised credentials against ePHI.
Detect and report atypical account behavior on systems with ePHI so privacy/security teams can investigate before harm spreads.
How this control shows up in healthcare and HIPAA-covered environments.
Multiple accounts open a VIP chart without care relationship. AC-2(12) atypical access alerts hit privacy within minutes for sanctions review — beyond waiting for a complaint.
Coder account downloads unusually large claim files at 03:00 from a new country. Atypical usage monitoring flags IdP+app anomalies for containment.
Disabled account somehow authenticates via legacy LDAP app. Atypical 'disabled account success' use case fires for incident response.
HIPAA activity review (§164.308(a)(1)(ii)(D)) is often weak. AC-2(12) evidence should show proactive anomaly detection, not only random sampling months later.
How this NIST control supports HIPAA Security Rule expectations.
No. Reviews are periodic certification; this enhancement requires ongoing monitoring for atypical usage with reporting.
Capability matters more than brand — SIEM correlation and EHR privacy tools can meet intent if indicators and response exist.
AU-6 is broader audit review; AC-2(12) focuses specifically on atypical account usage patterns.
Related controls that commonly accompany AC-2(12).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.