For-cause termination of EHR analyst
Analyst escorted out for suspected record sales. AC-2(13) runbook disables IdP, EHR, VPN, and badge within minutes — not the next business day’s standard leaver queue.
AC-2(13) enhances base AC-2 by disabling accounts of individuals who pose a significant risk within an organization-defined time period of discovery. Base AC-2 and AC-2(3) cover routine disable/inactivity; this enhancement targets accelerated disable when someone becomes high-risk — for-cause termination, credible insider threat, sanction list hits, or active investigation — so ePHI access stops before standard JML SLAs would finish.
Upon discovering that an individual poses significant risk, disable their ePHI-related accounts within a short, defined timeframe — faster than routine offboarding.
How this control shows up in healthcare and HIPAA-covered environments.
Analyst escorted out for suspected record sales. AC-2(13) runbook disables IdP, EHR, VPN, and badge within minutes — not the next business day’s standard leaver queue.
Monthly LEIE check flags a billing employee. High-risk disable suspends claims-system and EHR access pending adjudication under PS-3/AC-2(13).
Anonymous tip that a nurse is photographing VIP charts. Security declares high-risk; accounts disabled same shift while privacy investigates — atypical monitoring (AC-2(12)) may have contributed.
Compare involuntary termination timestamps to access-disable timestamps. Multi-day gaps for for-cause exits are classic AC-2(13)/HIPAA termination findings.
How this NIST control supports HIPAA Security Rule expectations.
AC-2(3) disables accounts under routine defined circumstances (e.g., inactivity). AC-2(13) accelerates disable specifically when the individual poses significant risk.
When risk is significant, disable access first per your authority matrix; coordinate documentation with HR/legal in parallel.
Often yes — if the person should not access ePHI during leave, treat as high-risk or LOA disable under defined triggers.
Related controls that commonly accompany AC-2(13).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.