AC-2(7) Access Control

Privileged User Accounts

Critical Risk Moderate Medium Cost

AC-2(7) enhances base AC-2 by requiring establishment and administration of privileged user accounts under an organization-defined usage policy — typically separate from non-privileged accounts used for routine duties. Base AC-2 manages accounts generally; this enhancement forces a privileged-account program so EHR/domain admins do not browse email or the web while holding standing power over ePHI infrastructure.

Control Objective

Issue and tightly govern distinct privileged accounts for administrative duties on ePHI systems, separate from day-to-day user accounts.

Implementation Guidance

  1. Inventory privileged functions: domain, EHR security, DB, cloud tenant, network, backup restore.
  2. Issue separate privileged IDs (e.g., jsmith vs jsmith-a); ban using privileged ID for email/web/Office.
  3. Require phishing-resistant MFA on privileged accounts.
  4. Restrict privileged logon to hardened admin workstations or PAM only.
  5. Review privileged membership monthly; remove unused elevation paths.
  6. Prohibit privileged accounts for routine chart review; use standard clinical ID.
  7. Vault and rotate privileged passwords; prefer check-out.
  8. Define sanctions for shared privileged credentials.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Dual-hatted clinical informaticist

Informaticist charts as a clinician and also configures order sets. AC-2(7) gives a separate build/admin account used only in the non-prod or controlled build session — not while reading personal email.

Helpdesk with Domain Admin

Tier-2 tech historically used one ID for tickets and ADUC. Split accounts: standard for ITSM, privileged only via PAM jump host for AD changes affecting clinical OUs.

Cloud EHR tenant owner

Tenant admin rights move to a dedicated cloud-only privileged identity with conditional access — not the user’s daily Microsoft 365 account.

Best Practices

  • One person, two accounts: standard + privileged.
  • Privileged IDs blocked from internet/email where feasible.
  • Monthly privileged access review.
  • Admin workstations / PAW for privileged use.
  • No shared 'Administrator' for humans.
  • Onboard/offboard privileged IDs with HR events.

Common Gaps & Violations

  • Single account used for charting and domain admin.
  • Privileged IDs allowed on any workstation.
  • Shared break-glass used as daily admin.
  • Contractors given standing privileged IDs without review.
  • Privileged accounts missing from termination checklists.

Required Documentation

  • Privileged account usage policy (AC-2(7))
  • Privileged account inventory and owners
  • PAW/PAM requirements
  • Monthly review evidence
  • MFA and logon restriction configs

How to Test & Validate

  1. Sample admins: confirm separate privileged IDs exist.
  2. Attempt privileged logon from a standard workstation — expect deny if PAW required.
  3. Verify privileged ID cannot access email/web if policy says so.
  4. Recheck last monthly privileged review remediations.
  5. Confirm terminated admins lost both IDs.

Audit Considerations

Ask “do your EHR security admins use the same account to read mail?” Separate privileged accounts with restrictions are expected evidence for AC-2(7).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — privileged functions need stricter identification and control.
  • 164.308(a)(3) Workforce Security — authorization/supervision of workforce with elevated duties.
  • 164.308(a)(4) Information Access Management — isolate powerful access roles.
  • 164.312(d) Person or Entity Authentication — privileged accounts warrant stronger authentication.

Compliance Tips

  • Put privileged-account attestation in the monthly IAM packet.
  • Block legacy protocols on privileged IDs.
  • Align AC-2(7) with AC-6 and AC-5 conflict rules.

Frequently Asked Questions

Can one shared 'EHRAdmin' account satisfy AC-2(7)?

No. Privileged user accounts should be attributable to individuals; shared IDs break accountability.

Do service accounts fall under AC-2(7)?

Govern them as privileged non-person accounts with owners, but the enhancement emphasizes privileged user accounts and usage policy for people.

Is a separate AD group enough without a separate account?

Group membership alone still leaves daily browsing on a powerful session. Separate accounts plus logon restrictions better match the enhancement intent.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(7)
  • Related controls: AC-2, AC-5, AC-6, IA-2, IA-5, CM-7

Need Help Implementing AC-2(7)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.