AC-2(13) Access Control

Disable Accounts for High-Risk Individuals

Critical Risk Moderate Low Cost

AC-2(13) enhances base AC-2 by disabling accounts of individuals who pose a significant risk within an organization-defined time period of discovery. Base AC-2 and AC-2(3) cover routine disable/inactivity; this enhancement targets accelerated disable when someone becomes high-risk — for-cause termination, credible insider threat, sanction list hits, or active investigation — so ePHI access stops before standard JML SLAs would finish.

Control Objective

Upon discovering that an individual poses significant risk, disable their ePHI-related accounts within a short, defined timeframe — faster than routine offboarding.

Implementation Guidance

  1. Define high-risk triggers: for-cause/involuntary termination, workplace violence threat, credible data theft suspicion, OIG exclusion affecting access roles, failed critical screening, law-enforcement hold per counsel.
  2. Set aggressive SLAs (often immediate to under one hour) for IdP/EHR/VPN/email disable.
  3. Create a rapid-disable runbook with after-hours contacts (IAM, security, HR, house supervisor).
  4. Preserve accounts in disabled state for investigation; do not delete evidence prematurely.
  5. Coordinate with legal/HR before tipping off subjects when investigation requires stealth — still disable access paths that enable harm.
  6. Extend to contractors and vendors posing significant risk.
  7. Test tabletop the runbook quarterly.
  8. Record decision authority who can declare 'high-risk disable'.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

For-cause termination of EHR analyst

Analyst escorted out for suspected record sales. AC-2(13) runbook disables IdP, EHR, VPN, and badge within minutes — not the next business day’s standard leaver queue.

OIG exclusion discovered

Monthly LEIE check flags a billing employee. High-risk disable suspends claims-system and EHR access pending adjudication under PS-3/AC-2(13).

Credible insider threat tip

Anonymous tip that a nurse is photographing VIP charts. Security declares high-risk; accounts disabled same shift while privacy investigates — atypical monitoring (AC-2(12)) may have contributed.

Best Practices

  • Written triggers and authority matrix.
  • Sub-hour SLA for critical systems.
  • After-hours rapid response roster.
  • Preserve forensic evidence.
  • Include badges and remote access.
  • Tabletop with HR and legal.

Common Gaps & Violations

  • Same 24–72h SLA for all terminations including for-cause.
  • HR notifies IT days later.
  • Email disabled but EHR left active.
  • No after-hours procedure.
  • Contractors excluded from rapid disable.

Required Documentation

  • High-risk individual disable procedure (AC-2(13))
  • Trigger definitions and decision authority
  • Rapid-disable runbook and contact tree
  • SLA metrics and sample events
  • Coordination protocol with HR/legal/privacy

How to Test & Validate

  1. Tabletop a for-cause termination after hours; time the disable steps.
  2. Review real for-cause cases for SLA compliance.
  3. Confirm EHR and VPN in the critical path checklist.
  4. Verify evidence preservation steps.
  5. Ensure contractors appear in the runbook.

Audit Considerations

Compare involuntary termination timestamps to access-disable timestamps. Multi-day gaps for for-cause exits are classic AC-2(13)/HIPAA termination findings.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(C) Termination Procedures — procedures for ending access when employment ends; high-risk cases demand accelerated execution.
  • 164.308(a)(1)(ii)(B) Risk Management — respond to significant insider risk promptly.
  • 164.312(a)(1) Access Control — remove ability to access ePHI when authorization is withdrawn.
  • 164.308(a)(6) Security Incident Procedures — high-risk disable often runs inside incident response.

Compliance Tips

  • Put 'for-cause = immediate disable' in both HR and IT policies.
  • Pre-stage emergency IdP roles for on-call security to disable accounts.
  • Measure median minutes-to-disable for high-risk events as a KPI.

Frequently Asked Questions

How is AC-2(13) different from AC-2(3)?

AC-2(3) disables accounts under routine defined circumstances (e.g., inactivity). AC-2(13) accelerates disable specifically when the individual poses significant risk.

Must we disable before HR finishes paperwork?

When risk is significant, disable access first per your authority matrix; coordinate documentation with HR/legal in parallel.

Does paid administrative leave count?

Often yes — if the person should not access ePHI during leave, treat as high-risk or LOA disable under defined triggers.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(13)
  • Related controls: AC-2, AC-2(3), PS-4, IR-4, AU-6, PS-3

Need Help Implementing AC-2(13)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.