AC-2(3) Access Control

Disable Accounts

High Risk Moderate Low Cost

AC-2(3) enhances base AC-2 by requiring the organization to disable accounts within an organization-defined time period when the accounts meet organization-defined circumstances (commonly inactivity, end of temporary need, or other disable conditions). Base AC-2 says disable/remove as part of lifecycle; this enhancement forces explicit, often automated, disable triggers and clocks so dormant EHR and VPN accounts do not remain attackable.

Control Objective

Disable accounts that meet defined conditions — especially inactivity and expired need — within a documented timeframe so unused ePHI access cannot persist.

Implementation Guidance

  1. Define disable circumstances: inactivity (e.g., 30/45/90 days by risk), LOA, contract end, failed screening, security incident hold.
  2. Set stricter clocks for privileged and remote-access accounts than for standard clinical users.
  3. Automate disable from IdP last-logon reports into account status; push to EHR.
  4. Notify managers before disable; allow justified reactivation with approval.
  5. Distinguish disable (reversible) from remove/delete (after retention).
  6. Exclude service accounts carefully — monitor differently; do not leave interactive dormant admins.
  7. Align LOA and seasonal clinician schedules so expected gaps do not cause unsafe re-enable chaos.
  8. Document emergency reactivation path with logging.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Locum who never returned

A locum physician last logged into the EHR 75 days ago. AC-2(3) inactivity rule disables the account at day 60; reactivation needs medical staff office approval.

VPN zombie after remote project

Coder finished a remote CDI project; VPN idle 40 days. Automated disable closes the tunnel into the clinical network even though HR still shows active employment.

Privileged admin on leave

Domain admin on 8-week LOA. Privileged inactivity policy disables the admin ID within 14 idle days; standard email account may follow a longer clock.

Best Practices

  • Publish inactivity thresholds by account class.
  • Warn users/managers before disable.
  • Faster clocks for privileged and external access.
  • Monthly dormant-account metrics.
  • Reactivation requires fresh approval for high-risk roles.
  • Keep disable distinct from HR termination (still required).

Common Gaps & Violations

  • No inactivity disable — only termination disable.
  • Thresholds so long they are meaningless (e.g., 365 days for admins).
  • EHR not included in dormant scans.
  • Disabled accounts silently re-enabled by local admins.
  • Service accounts interactive and never reviewed.

Required Documentation

  • Account disablement procedure (AC-2(3))
  • Inactivity and other disable triggers by account type
  • Automation/job schedules and samples
  • Reactivation approval workflow
  • Exception list (monitored service accounts)

How to Test & Validate

  1. Identify an account past inactivity threshold; confirm disabled.
  2. Verify privileged thresholds are stricter.
  3. Sample reactivations for approval evidence.
  4. Confirm EHR reflects IdP disabled status.
  5. Review exceptions for business justification.

Audit Considerations

Compare last-logon reports to active flags. Large populations of never-logged-in or long-dormant active EHR users indicate AC-2(3) is not operating.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(C) Termination Procedures — disable is the immediate control when access must stop; inactivity is a related hygiene control.
  • 164.312(a)(1) Access Control — limit system access to authorized users; dormant IDs undermine that.
  • 164.308(a)(4)(ii)(C) Access Establishment and Modification — modify/disable access when conditions change.
  • 164.308(a)(1) Risk Analysis — dormant account abuse is a recognized threat to ePHI.

Compliance Tips

  • Start with 30-day disable for VPN and privileged; tune clinical thresholds with workforce input.
  • Feed dormant reports into access reviews (AC-2).
  • Never equate 'disabled' with 'deleted' for legal hold accounts — document holds.

Frequently Asked Questions

Is AC-2(3) only about inactivity?

Inactivity is the common case, but NIST allows any organization-defined circumstances that should force disable within a set time.

What if clinicians travel for months?

Use LOA or temporary-status flags so expected absence does not look like abandonment — or require manager attestation before auto-disable.

Disable vs remove?

Disable quickly to stop access; remove after retention/review so identifiers and audit history remain coherent.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(3)
  • Related controls: AC-2, AC-2(2), AC-2(13), PS-4, AU-6

Need Help Implementing AC-2(3)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.