AC-2(5) Access Control

Inactivity Logout

High Risk Easy Low Cost

AC-2(5) enhances base AC-2 by requiring the system to automatically log out users after an organization-defined time period of inactivity. Base AC-2 manages accounts; this enhancement addresses the live session risk when a clinician walks away from a charting workstation — a classic HIPAA shoulder-surfing and impersonation scenario that account lifecycle controls alone do not solve.

Control Objective

Terminate or lock idle interactive sessions to ePHI systems within a defined inactivity period so unattended sessions cannot be abused.

Implementation Guidance

  1. Set inactivity timeouts for EHR, VDI, VPN portals, email on shared workstations, and admin consoles — shorter for high-sensitivity contexts.
  2. Prefer lock-then-reauthenticate patterns that do not lose unsaved work unsafely; align with clinical workflow and AC-11 session lock.
  3. Enforce via IdP session policies, EHR settings, and OS GPO/MDM — defense in depth.
  4. Ban 'never timeout' exceptions except documented kiosk architectures with compensating controls.
  5. Educate clinical staff on saving work; tune timeouts with nursing leadership to avoid unsafe workarounds.
  6. Apply to remote/telehealth sessions and home VDI.
  7. Monitor for clients that suppress idle timers.
  8. Document different timers (e.g., 5–15 min clinical floor vs longer for dedicated private offices if risk analysis allows).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nursing station walk-away

RN steps away mid-chart. AC-2(5) EHR inactivity logout at 10 minutes prevents the next person at the shared PC from documenting under the wrong identity.

OR control desk leftover session

Scheduler leaves a perioperative system open overnight. Idle logout closes the session so environmental services or early staff cannot browse tomorrow’s surgical board with full demographics.

Home VDI left connected

Coder’s home VDI idles while they step out. Session policy logs out, reducing household member or malware use of an open ePHI desktop.

Best Practices

  • Risk-based timeouts; floors shorter than private offices.
  • Combine with screen lock (AC-11) and clear desk expectations.
  • Test after EHR upgrades — timers often reset.
  • Address shared workstations explicitly.
  • Prohibit timeout defeat tools.
  • Align remote access timers with on-prem.

Common Gaps & Violations

  • EHR timeout disabled 'for productivity'.
  • OS lock at 30 minutes but EHR never logs out.
  • Shared generic sessions that inactivity logout cannot attribute.
  • Citrix/VDI policies not applied to clinical OU.
  • Exceptions granted permanently with no review.

Required Documentation

  • Inactivity logout / session timeout standard (AC-2(5))
  • Timer matrix by system and location type
  • Configuration baselines (EHR, GPO, IdP, VDI)
  • Approved exceptions with compensating controls
  • Periodic validation test records

How to Test & Validate

  1. Idle a test EHR session; confirm logout/lock at policy time.
  2. Repeat on VDI and VPN portal.
  3. Spot-check clinical workstations for local overrides.
  4. Review exception list currency.
  5. Confirm upgrade regression test includes timeouts.

Audit Considerations

Surveyors often watch nursing stations for unattended open charts. Technical timeout evidence plus floor observation tells the AC-2(5) story.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(iii) Automatic Logoff — required implementation specification to terminate sessions after predetermined time of inactivity.
  • 164.310(b) Workstation Use — policies for proper workstation use complement idle logout.
  • 164.310(c) Workstation Security — physical safeguards on workstations pair with session timeout.
  • 164.312(a)(1) Access Control — automatic logoff supports limiting access to authorized users.

Compliance Tips

  • Map AC-2(5) explicitly to HIPAA Automatic Logoff in your SSP.
  • Involve clinical informatics when setting minutes — buy-in prevents shadow IT.
  • Treat timeout bypass as a security incident.

Frequently Asked Questions

Is AC-2(5) the same as AC-11?

Closely related. AC-11 focuses on session lock; AC-2(5) emphasizes automatic logout after inactivity as an account/session management enhancement. Implement both coherently.

Does HIPAA require a specific number of minutes?

No fixed federal minute count — define based on risk and document. Many hospitals use short timers on shared clinical devices.

What about devices that cannot log out safely mid-procedure?

Document compensating controls (location, supervision, shorter physical access) and minimize interactive ePHI where possible.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(5)
  • Related controls: AC-11, AC-12, IA-11, SI-4

Need Help Implementing AC-2(5)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.