Locum who never returned
A locum physician last logged into the EHR 75 days ago. AC-2(3) inactivity rule disables the account at day 60; reactivation needs medical staff office approval.
AC-2(3) enhances base AC-2 by requiring the organization to disable accounts within an organization-defined time period when the accounts meet organization-defined circumstances (commonly inactivity, end of temporary need, or other disable conditions). Base AC-2 says disable/remove as part of lifecycle; this enhancement forces explicit, often automated, disable triggers and clocks so dormant EHR and VPN accounts do not remain attackable.
Disable accounts that meet defined conditions — especially inactivity and expired need — within a documented timeframe so unused ePHI access cannot persist.
How this control shows up in healthcare and HIPAA-covered environments.
A locum physician last logged into the EHR 75 days ago. AC-2(3) inactivity rule disables the account at day 60; reactivation needs medical staff office approval.
Coder finished a remote CDI project; VPN idle 40 days. Automated disable closes the tunnel into the clinical network even though HR still shows active employment.
Domain admin on 8-week LOA. Privileged inactivity policy disables the admin ID within 14 idle days; standard email account may follow a longer clock.
Compare last-logon reports to active flags. Large populations of never-logged-in or long-dormant active EHR users indicate AC-2(3) is not operating.
How this NIST control supports HIPAA Security Rule expectations.
Inactivity is the common case, but NIST allows any organization-defined circumstances that should force disable within a set time.
Use LOA or temporary-status flags so expected absence does not look like abandonment — or require manager attestation before auto-disable.
Disable quickly to stop access; remove after retention/review so identifiers and audit history remain coherent.
Related controls that commonly accompany AC-2(3).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.