AC-2(4) Access Control

Automated Audit Actions

High Risk Moderate Medium Cost

AC-2(4) enhances base AC-2 by requiring automated auditing of account creation, modification, enabling, disabling, and removal actions. Base AC-2 expects monitoring of account use; this enhancement specifically demands automated audit records of the lifecycle events themselves — who provisioned or changed an account — which is essential when investigating inappropriate ePHI access.

Control Objective

Automatically record account lifecycle events (create/modify/enable/disable/remove) for ePHI-related systems so investigators can prove who changed access and when.

Implementation Guidance

  1. Enable directory and IdP audit logs for user/group/role changes; retain per policy.
  2. Capture EHR security console actions that create or alter users/roles.
  3. Forward logs to SIEM with alerts on privileged account changes and after-hours provisioning.
  4. Include actor, target, action, timestamp, and source host/app in each event.
  5. Protect audit streams from tampering (AU-9); admins should not freely purge account-change logs.
  6. Correlate ticket IDs in automation so each change links to approval.
  7. Cover SaaS apps holding ePHI (billing, telehealth) via admin audit APIs.
  8. Periodically test that disables and role removals actually generate events.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Mystery EHR admin created

An unexplained admin appears in Epic/Cerner. AC-2(4) IdP+EHR audit shows which security analyst created it and whether a ticket existed — base monitoring of chart access alone would miss the provisioning act.

Silent role add on weekend

Group membership granting HIM release-of-information rights changes Saturday night. SIEM alert from automated account-audit events triggers review before Monday bulk disclosures.

Terminated user still enabled

Investigation of a breach rumor uses AC-2(4) logs to prove the account was disabled Tuesday 16:12 by automation — narrowing the access window.

Best Practices

  • Centralize IdP, EHR, and PAM account-change logs.
  • Alert on privileged lifecycle events.
  • Require ticket reference in provisioning automation.
  • Retain logs at least as long as access-review cycles demand.
  • Include failed provisioning attempts.
  • Review audit coverage when onboarding new ePHI SaaS.

Common Gaps & Violations

  • EHR user admin actions not logged or logs overwritten quickly.
  • Only successful logons audited — not account creates.
  • Local AD auditing off on domain controllers.
  • No alerting on privileged group changes.
  • SaaS admin portals outside the SIEM.

Required Documentation

  • Account audit logging standard (AC-2(4))
  • Log sources and retention matrix
  • SIEM use cases / alert definitions
  • Sample lifecycle event records
  • Integrity/protection controls for audit data

How to Test & Validate

  1. Create/modify/disable a test account; confirm events in SIEM.
  2. Alter a privileged group; confirm alert.
  3. Verify EHR security audit trail for user admin actions.
  4. Check retention against policy.
  5. Attempt to confirm non-admin users cannot delete these logs.

Audit Considerations

HIPAA audit controls (§164.312(b)) are often tested with account-change evidence. If you cannot show who granted EHR access last month, AC-2(4) is incomplete.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — hardware, software, and procedural mechanisms that record and examine activity in systems with ePHI.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — review of audit logs includes account administration activity.
  • 164.312(a)(1) Access Control — accountability for who received access.
  • 164.308(a)(4) Information Access Management — evidence of establishment/modification of access.

Compliance Tips

  • Add 'account lifecycle' as a named SIEM use-case family.
  • Keep a 90-day hot retain for IAM events used in access investigations.
  • Pair AC-2(4) with AU-2 event definitions so account events are in scope formally.

Frequently Asked Questions

Is logon logging enough for AC-2(4)?

No. This enhancement targets automated audit of account create/modify/enable/disable/remove — not only session use.

Do we need this if HR creates accounts?

Yes. Wherever accounts are created or changed — HRIS, IdP, EHR — those actions need automated audit trails.

How does this relate to AU-2?

AU-2 defines auditable events; AC-2(4) ensures account-management actions are among those automatically recorded.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(4)
  • Related controls: AC-2, AU-2, AU-3, AU-6, AU-9

Need Help Implementing AC-2(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.