Mystery EHR admin created
An unexplained admin appears in Epic/Cerner. AC-2(4) IdP+EHR audit shows which security analyst created it and whether a ticket existed — base monitoring of chart access alone would miss the provisioning act.
AC-2(4) enhances base AC-2 by requiring automated auditing of account creation, modification, enabling, disabling, and removal actions. Base AC-2 expects monitoring of account use; this enhancement specifically demands automated audit records of the lifecycle events themselves — who provisioned or changed an account — which is essential when investigating inappropriate ePHI access.
Automatically record account lifecycle events (create/modify/enable/disable/remove) for ePHI-related systems so investigators can prove who changed access and when.
How this control shows up in healthcare and HIPAA-covered environments.
An unexplained admin appears in Epic/Cerner. AC-2(4) IdP+EHR audit shows which security analyst created it and whether a ticket existed — base monitoring of chart access alone would miss the provisioning act.
Group membership granting HIM release-of-information rights changes Saturday night. SIEM alert from automated account-audit events triggers review before Monday bulk disclosures.
Investigation of a breach rumor uses AC-2(4) logs to prove the account was disabled Tuesday 16:12 by automation — narrowing the access window.
HIPAA audit controls (§164.312(b)) are often tested with account-change evidence. If you cannot show who granted EHR access last month, AC-2(4) is incomplete.
How this NIST control supports HIPAA Security Rule expectations.
No. This enhancement targets automated audit of account create/modify/enable/disable/remove — not only session use.
Yes. Wherever accounts are created or changed — HRIS, IdP, EHR — those actions need automated audit trails.
AU-2 defines auditable events; AC-2(4) ensures account-management actions are among those automatically recorded.
Related controls that commonly accompany AC-2(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.