ED trauma without prior assignment
ED physician break-glasses into a sealed chart to treat an unresponsive patient; justification captured; privacy reviews within 24 hours and closes as appropriate.
AC-3(10) requires employing audited override of access control mechanisms under organization-defined conditions — typically emergency access when normal permissions would block care. Healthcare break-glass must never be a silent backdoor: overrides need strong authentication, captured rationale, real-time or near-real-time logging, and mandatory after-action review so VIP snooping cannot hide behind 'emergency.'
Permit exceptional access to ePHI when clinically or operationally justified while ensuring every override is attributable, logged, and reviewed.
How this control shows up in healthcare and HIPAA-covered environments.
ED physician break-glasses into a sealed chart to treat an unresponsive patient; justification captured; privacy reviews within 24 hours and closes as appropriate.
Staff use override to view a public figure's record without care relationship. Audit alert fires; investigation confirms violation — AC-3(10) evidence supports sanctions.
During contingency, temporary override opens read-only charts for downtime clinics; each use is logged and bulk-reviewed after systems restore.
Break-glass is expected in clinical systems; assessors judge whether it is controlled and audited. Silent or perpetual emergency rights fail AC-3(10) and HIPAA audit expectations.
How this NIST control supports HIPAA Security Rule expectations.
Emergency access procedure is an addressable access-control specification — implement if reasonable and appropriate, which it usually is for EHRs.
No. AC-3(10) requires auditing; identity must be known.
Minutes to hours matching the emergency — not days. Re-auth if care continues.
Related controls that commonly accompany AC-3(10).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.