PACS vendor go-live weekend
OEM needs admin Friday–Sunday. AC-2(2) issues a named account expiring Monday 06:00; automation disables it even if the ticket is forgotten.
AC-2(2) enhances base AC-2 by requiring automated mechanisms to create, activate, manage, and disable temporary and emergency accounts. Base AC-2 acknowledges these account types; this enhancement demands automation so temp/vendor/break-glass IDs cannot linger indefinitely after a go-live weekend or disaster drill — a frequent healthcare audit finding.
Ensure temporary and emergency accounts that can reach ePHI are issued with automated expiry, tracked ownership, and automatic disable when the window ends.
How this control shows up in healthcare and HIPAA-covered environments.
OEM needs admin Friday–Sunday. AC-2(2) issues a named account expiring Monday 06:00; automation disables it even if the ticket is forgotten.
Downtime procedure checks out emergency EHR admin via PAM. Session ends; account returns to disabled vault state automatically — base AC-2 alone often left the password on a sticky note.
Agency RT needs 14-day EHR access. Temporary account auto-expires on day 15 unless staffing renews with approval.
Auditors hunt for forever-on vendor and break-glass IDs. Automated expiry evidence is stronger than a policy paragraph promising manual cleanup.
How this NIST control supports HIPAA Security Rule expectations.
AC-2(1) automates general account management; AC-2(2) specifically automates temporary and emergency account create/manage/disable.
Prefer named, vaulted, auto-expiring credentials with logging. Shared static passwords fail accountability.
Yes — assign term end dates and automate disable at graduation/withdrawal.
Related controls that commonly accompany AC-2(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.