Bulk research extract from EHR warehouse
Analyst requests 50,000-patient limited dataset. Dual authorization requires data steward plus privacy officer approval before the export job runs.
AC-3(2) requires enforcing dual authorization for organization-defined privileged commands and/or other organization-defined actions. Healthcare use cases include enabling enterprise break-glass, granting security-admin roles, releasing large ePHI extracts, unlocking sealed VIP charts for non-care reasons, or changing production encryption keys. A single compromised or malicious account should not complete these actions alone.
Require two authorized individuals to approve and complete defined high-risk actions that could expose, alter, or weaken protections for ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Analyst requests 50,000-patient limited dataset. Dual authorization requires data steward plus privacy officer approval before the export job runs.
IT builds a role; security leadership must approve assignment to a named person before the role activates — AC-3(2) blocks one admin from creating peers unchecked.
Non-treatment access request requires treating provider attestation and privacy officer dual authorization before override (pairs with AC-3(10) auditing).
OCR and assessors look for evidence that high-risk ePHI actions cannot be solo-executed. Email 'FYI' chains without system enforcement are weak evidence.
How this NIST control supports HIPAA Security Rule expectations.
No. MFA proves one user; dual authorization requires two people (or two distinct authorized roles) for the action.
Use dual control for the few Critical actions and document when the privacy officer or practice administrator is the second approver.
Yes if the system blocks the action until the second approval is recorded — informal chat approval does not.
Related controls that commonly accompany AC-3(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.