AC-3(10) Access Control

AC-3(10) Audited Override of Access Control Mechanisms

Critical Risk Moderate Medium Cost

AC-3(10) requires employing audited override of access control mechanisms under organization-defined conditions — typically emergency access when normal permissions would block care. Healthcare break-glass must never be a silent backdoor: overrides need strong authentication, captured rationale, real-time or near-real-time logging, and mandatory after-action review so VIP snooping cannot hide behind 'emergency.'

Control Objective

Permit exceptional access to ePHI when clinically or operationally justified while ensuring every override is attributable, logged, and reviewed.

Implementation Guidance

  1. Define when override is allowed (life-threatening emergency, downtime contingency, declared incident) and when it is not (curiosity, convenience).
  2. Implement break-glass roles or buttons that elevate only temporarily.
  3. Require MFA and a typed clinical/operational justification at override time.
  4. Log user, patient/object, time, duration, actions taken, and workstation.
  5. Alert privacy/security in near real time for VIP or high-sensitivity overrides.
  6. Auto-expire elevated rights; force re-authentication for continued use.
  7. Complete post-event review within a defined window (e.g., 24–72 hours).
  8. Discipline confirmed inappropriate overrides; feed patterns into training.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

ED trauma without prior assignment

ED physician break-glasses into a sealed chart to treat an unresponsive patient; justification captured; privacy reviews within 24 hours and closes as appropriate.

Inappropriate VIP browse

Staff use override to view a public figure's record without care relationship. Audit alert fires; investigation confirms violation — AC-3(10) evidence supports sanctions.

Ransomware recovery

During contingency, temporary override opens read-only charts for downtime clinics; each use is logged and bulk-reviewed after systems restore.

Best Practices

  • Break-glass is temporary and monitored.
  • Justification required up front.
  • Near-real-time alerts for sensitive patients.
  • Formal after-action review.
  • Never share a generic break-glass password.
  • Report metrics: overrides per month, inappropriate rate.

Common Gaps & Violations

  • Standing 'emergency' AD group always active.
  • Override with no reason code.
  • Logs exist but nobody reviews them.
  • Shared break-glass username/password on a sticky note.
  • Override used daily for missing role design instead of fixing RBAC.

Required Documentation

  • Break-glass / audited override procedure
  • Technical configuration of override mechanism
  • Alerting and review workflow
  • Sample override logs and after-action records
  • Sanctions examples (redacted) for misuse

How to Test & Validate

  1. Perform a test override in a non-prod or approved test patient; confirm justification and log fields.
  2. Verify elevation expires automatically.
  3. Confirm alert generation for VIP flag test case.
  4. Sample recent overrides for completed reviews.
  5. Attempt override without MFA if MFA is required; confirm fail.

Audit Considerations

Break-glass is expected in clinical systems; assessors judge whether it is controlled and audited. Silent or perpetual emergency rights fail AC-3(10) and HIPAA audit expectations.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — emergency access procedure is an addressable implementation specification under access control.
  • 164.312(b) Audit Controls — record and examine override activity.
  • 164.308(a)(1) Risk Management — emergency access is a treated residual risk requiring monitoring.
  • 164.308(a)(4) Information Access Management — exceptional access still must be governed.

Compliance Tips

  • Never use break-glass as a substitute for fixing slow access provisioning.
  • Dashboard inappropriate-override rate for compliance committee.
  • Pair with AC-3(2) dual authorization for non-clinical emergency unlocks (e.g., media/legal).

Frequently Asked Questions

Is break-glass required by HIPAA?

Emergency access procedure is an addressable access-control specification — implement if reasonable and appropriate, which it usually is for EHRs.

Can overrides be anonymous for clinician speed?

No. AC-3(10) requires auditing; identity must be known.

How long should elevation last?

Minutes to hours matching the emergency — not days. Re-auth if care continues.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-3(10)
  • HIPAA § 164.312(a)(2)(ii) Emergency Access Procedure
  • Related: AC-2, AC-3, AU-2, AU-6, IR-4

Need Help Implementing AC-3(10)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.