Dual-hatted clinical informaticist
Informaticist charts as a clinician and also configures order sets. AC-2(7) gives a separate build/admin account used only in the non-prod or controlled build session — not while reading personal email.
AC-2(7) enhances base AC-2 by requiring establishment and administration of privileged user accounts under an organization-defined usage policy — typically separate from non-privileged accounts used for routine duties. Base AC-2 manages accounts generally; this enhancement forces a privileged-account program so EHR/domain admins do not browse email or the web while holding standing power over ePHI infrastructure.
Issue and tightly govern distinct privileged accounts for administrative duties on ePHI systems, separate from day-to-day user accounts.
How this control shows up in healthcare and HIPAA-covered environments.
Informaticist charts as a clinician and also configures order sets. AC-2(7) gives a separate build/admin account used only in the non-prod or controlled build session — not while reading personal email.
Tier-2 tech historically used one ID for tickets and ADUC. Split accounts: standard for ITSM, privileged only via PAM jump host for AD changes affecting clinical OUs.
Tenant admin rights move to a dedicated cloud-only privileged identity with conditional access — not the user’s daily Microsoft 365 account.
Ask “do your EHR security admins use the same account to read mail?” Separate privileged accounts with restrictions are expected evidence for AC-2(7).
How this NIST control supports HIPAA Security Rule expectations.
No. Privileged user accounts should be attributable to individuals; shared IDs break accountability.
Govern them as privileged non-person accounts with owners, but the enhancement emphasizes privileged user accounts and usage policy for people.
Group membership alone still leaves daily browsing on a powerful session. Separate accounts plus logon restrictions better match the enhancement intent.
Related controls that commonly accompany AC-2(7).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.