Helpdesk cannot edit EHR security roles
A Tier-1 analyst can reset passwords but cannot open the EHR security workbench. AC-3(1) keeps role design and break-glass config behind a security-admin group only.
AC-3(1) requires the system to employ an access control policy that restricts access to privileged functions and security-relevant information to authorized individuals. In healthcare, privileged functions include EHR role configuration, break-glass enablement, identity provider admin, database DDL/DML on ePHI stores, and network ACL changes that open clinical segments. Restricting who can invoke these functions prevents a standard clinician or helpdesk account from quietly becoming a system-wide ePHI threat.
Ensure only explicitly authorized individuals can execute privileged or security-relevant functions that could alter access paths, configurations, or protections around ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
A Tier-1 analyst can reset passwords but cannot open the EHR security workbench. AC-3(1) keeps role design and break-glass config behind a security-admin group only.
App developers deploy via pipeline but cannot GRANT SELECT on the live ePHI schema. Privileged DBA functions stay with a named production DBA role.
A practice manager with scheduling admin rights cannot create enterprise app registrations that would federate new ePHI consumers — IdP privileged functions remain centralized.
Assessors ask who can change who sees ePHI. Broad security-admin assignment and unaudited privileged menus are classic AC-3(1) findings in healthcare.
How this NIST control supports HIPAA Security Rule expectations.
Any action that can create accounts, change roles, alter audit settings, decrypt or export bulk ePHI, or weaken security controls.
Prefer separation. If staffing forces overlap, use separate accounts, MFA, and heightened monitoring.
Only if the backend also denies the API/action — UI hiding alone is not enforcement.
Related controls that commonly accompany AC-3(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.