EHR security config change
Analyst needs User Security for a role fix. AC-2(6) JIT elevates for 2 hours after approval; standing 'EHR Security Admin' is no longer permanent on their account.
AC-2(6) enhances base AC-2 by requiring the organization to implement dynamic privilege management capabilities. Where base AC-2 and AC-6 assign relatively static roles, this enhancement adds the ability to grant, adjust, or revoke privileges dynamically based on context (time, task, approval, risk signal) — reducing standing power over ePHI systems.
Grant elevated privileges to ePHI and supporting systems dynamically for a task window, then remove them automatically — minimizing standing privileged access.
How this control shows up in healthcare and HIPAA-covered environments.
Analyst needs User Security for a role fix. AC-2(6) JIT elevates for 2 hours after approval; standing 'EHR Security Admin' is no longer permanent on their account.
Engineer checks out temporary rights to the interface engine host, restarts the HL7 process, and privileges drop — no 24/7 local admin on the ePHI broker.
UEBA flags anomalous behavior; dynamic privilege engine revokes elevated tokens while investigation proceeds, beyond simply disabling the whole account later.
Assessors look for standing admin populations. Showing JIT check-out metrics demonstrates AC-2(6) maturity beyond static RBAC spreadsheets.
How this NIST control supports HIPAA Security Rule expectations.
AC-6 is the least-privilege principle for assigned rights; AC-2(6) adds dynamic grant/adjust/revoke capabilities so privileges are not always standing.
RBAC is necessary but often static. Dynamic privilege management layers JIT/time-bound elevation on top.
Usually no — focus on privileged/admin functions. Clinical access stays role-based with reviews.
Related controls that commonly accompany AC-2(6).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.