AC-2(2) Access Control

Automated Temporary and Emergency Account Management

High Risk Moderate Medium Cost

AC-2(2) enhances base AC-2 by requiring automated mechanisms to create, activate, manage, and disable temporary and emergency accounts. Base AC-2 acknowledges these account types; this enhancement demands automation so temp/vendor/break-glass IDs cannot linger indefinitely after a go-live weekend or disaster drill — a frequent healthcare audit finding.

Control Objective

Ensure temporary and emergency accounts that can reach ePHI are issued with automated expiry, tracked ownership, and automatic disable when the window ends.

Implementation Guidance

  1. Define temporary (students, travelers, project vendors) vs emergency/break-glass account catalogs.
  2. Require end dates at creation; automate disable at expiry without relying on humans.
  3. Bind emergency accounts to PAM check-out with session recording and auto-check-in.
  4. Notify owners N days before expiry; auto-disable if not explicitly extended with approval.
  5. Prohibit standing 'vendoradmin' shared IDs; use named time-boxed accounts.
  6. After emergency use, auto-flag for post-use review (who, why, what was accessed).
  7. Integrate expiry with IdP conditional access and EHR user status.
  8. Report open temp/emergency accounts weekly to IAM and compliance.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

PACS vendor go-live weekend

OEM needs admin Friday–Sunday. AC-2(2) issues a named account expiring Monday 06:00; automation disables it even if the ticket is forgotten.

EHR break-glass during downtime

Downtime procedure checks out emergency EHR admin via PAM. Session ends; account returns to disabled vault state automatically — base AC-2 alone often left the password on a sticky note.

Traveling respiratory therapist

Agency RT needs 14-day EHR access. Temporary account auto-expires on day 15 unless staffing renews with approval.

Best Practices

  • Default deny permanent status for temp/emergency types.
  • Named accounts only; no shared break-glass passwords.
  • Session recording for emergency elevation.
  • Weekly inventory of non-expired temp IDs.
  • Extension requires re-approval, not silent renew.
  • Align with IR-4 for true emergencies.

Common Gaps & Violations

  • Emergency accounts permanently enabled 'just in case'.
  • Vendor accounts with no end date.
  • Manual disable process that is skipped after projects.
  • Shared break-glass password known to whole IT team.
  • No post-use review of emergency access.

Required Documentation

  • Temporary and emergency account procedure (AC-2(2))
  • Account type definitions and max durations
  • Automation/expiry configuration evidence
  • Break-glass / PAM check-out logs
  • Post-use review samples

How to Test & Validate

  1. Create a test temp account; confirm auto-disable at end date.
  2. Attempt extension without approval; expect block or ticket requirement.
  3. Review last quarter’s emergency check-outs for post-use reviews.
  4. Scan IdP for accounts tagged temp/emergency past expiry.
  5. Verify vendor go-live accounts from recent projects are disabled.

Audit Considerations

Auditors hunt for forever-on vendor and break-glass IDs. Automated expiry evidence is stronger than a policy paragraph promising manual cleanup.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — emergency access procedure is a required implementation specification; AC-2(2) operationalizes it with automation.
  • 164.308(a)(7)(ii)(C) Emergency Mode Operation — emergency access must still be controlled and ended.
  • 164.308(a)(3)(ii)(C) Termination Procedures — temp workforce and vendors need equivalent end-of-access discipline.
  • 164.308(a)(4) Information Access Management — limit access duration to need.

Compliance Tips

  • Cap emergency account lifetime in the IdP (e.g., 8–24 hours) unless re-checked out.
  • Put temp-account counts on the monthly IAM report.
  • Train service desk never to create vendor IDs without an end date field.

Frequently Asked Questions

How is AC-2(2) different from AC-2(1)?

AC-2(1) automates general account management; AC-2(2) specifically automates temporary and emergency account create/manage/disable.

Can break-glass be a shared password in a safe?

Prefer named, vaulted, auto-expiring credentials with logging. Shared static passwords fail accountability.

Do student accounts count as temporary?

Yes — assign term end dates and automate disable at graduation/withdrawal.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(2)
  • Related controls: AC-2, AC-2(1), AC-2(3), AU-6, IR-4

Need Help Implementing AC-2(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.