AC-2(9) Access Control

Restrictions on Use of Shared and Group Accounts

High Risk Moderate Medium Cost

AC-2(9) enhances base AC-2 by requiring restrictions on the use of shared and group accounts — authorizing such use only under organization-defined conditions and documenting the rationale. Base AC-2 prefers individual accounts; this enhancement confronts the healthcare reality of dept and nurse-station logins and demands tight limits so ePHI actions remain attributable.

Control Objective

Prohibit or strictly condition shared/group account use so access to ePHI remains individually accountable except where a documented exception is unavoidable.

Implementation Guidance

  1. Inventory shared/group/generic accounts in IdP, EHR, medical devices, and departmental apps.
  2. Eliminate shared clinical logins where the EHR supports fast-user switching or proximity badges (Imprivata-style).
  3. Define rare allowed cases (e.g., certain appliance admin, break-glass) with named owners and compensating logging.
  4. Ban shared accounts for email, VPN, and EHR charting as default policy.
  5. Require unique IDs for billing, coding, and disclosure staff without exception.
  6. Monitor shared account use; alert on interactive use of service accounts.
  7. Revalidate exceptions quarterly.
  8. Train managers that shared passwords violate both AC-2(9) and HIPAA unique user identification expectations.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

ED tracking board generic login

ED used one 'EDCharge' account on wall PCs. AC-2(9) replaces it with individual badge tap-in so every order and view maps to a person.

Shared HIM release mailbox login

ROI staff shared one EHR login to print disclosures. Restriction forces individual accounts; mailbox remains shared for email only without EHR rights.

Ultrasound machine service account

Device requires a local shared OS account. Exception documents the limitation, network isolation, and that clinical ePHI apps still use unique user auth where the modality supports it.

Best Practices

  • Default deny shared interactive accounts.
  • Badge/tap authentication for shared workstations.
  • Named owner for every unavoidable shared ID.
  • Quarterly exception reapproval.
  • Alert on interactive service-account logons.
  • Include medical devices in the inventory.

Common Gaps & Violations

  • Department passwords on sticky notes for EHR.
  • Shared 'coding' account for productivity.
  • Service accounts used by humans daily.
  • Exceptions never reviewed.
  • Vendors share one login across technicians.

Required Documentation

  • Shared/group account restriction policy (AC-2(9))
  • Inventory of approved exceptions with owners
  • Compensating controls per exception
  • Quarterly review records
  • Training acknowledgment samples

How to Test & Validate

  1. Scan for generic account names (dept, shared, clinic1).
  2. Observe clinical workstations for shared session behavior.
  3. Review exception list against live accounts.
  4. Confirm service accounts deny interactive logon where required.
  5. Sample disclosure/billing users for unique IDs.

Audit Considerations

HIPAA unique user identification makes shared EHR logins a high-visibility finding. AC-2(9) evidence should show elimination or tightly controlled exceptions.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(i) Unique User Identification — assign a unique name/number for identifying and tracking user identity.
  • 164.312(a)(1) Access Control — access only for authorized persons; sharing defeats authorization precision.
  • 164.312(b) Audit Controls — shared accounts make examination of activity unreliable.
  • 164.308(a)(3) Workforce Security — accountability for workforce actions.

Compliance Tips

  • Fund single sign-on / tap-and-go to remove the 'too slow to log in' excuse.
  • Make shared-account discovery part of monthly IAM hygiene.
  • Write device exceptions narrowly — not as a blanket clinical waiver.

Frequently Asked Questions

Are Active Directory security groups 'group accounts'?

No. Security groups for RBAC are expected. AC-2(9) targets shared login identities used by multiple people.

Can on-call share one break-glass account?

Prefer individual break-glass check-out. If a shared emergency account exists, restrict heavily, log heavily, and review after each use (see AC-2(2)).

What about medical devices that only support one login?

Document as an exception with network and physical compensating controls; push vendors toward unique user support.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2(9)
  • Related controls: AC-2, AC-2(10), IA-2, AU-2, AU-6

Need Help Implementing AC-2(9)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.