Nurse terminated mid-shift
HR marks involuntary exit; IdP disable fires within the hour; EHR session tokens fail refresh; VPN cert revoked — AC-3(8) meets the aggressive SLA.
AC-3(8) requires enforcing the revocation of access authorizations resulting from changes to security attributes of objects or subjects (e.g., role changes, clearance loss, employment end) within organization-defined time periods. Healthcare breaches frequently involve terminated staff or vendors whose EHR, VPN, and badge rights lingered. Revocation must be timely, complete across systems, and verified.
Withdraw ePHI access authorizations quickly and completely when subject or object security attributes change so former rights cannot be exercised beyond policy time limits.
How this control shows up in healthcare and HIPAA-covered environments.
HR marks involuntary exit; IdP disable fires within the hour; EHR session tokens fail refresh; VPN cert revoked — AC-3(8) meets the aggressive SLA.
Vendor accounts auto-expire Friday 17:00; Monday review confirms no residual PACS admin role remained.
Security attributes on the object change; prior discretionary Care Team views that conflict with the new seal are revoked automatically where the EHR supports it.
Comparing termination lists to active EHR users is a standard HIPAA assessment test. AC-3(8) evidence is the disable timestamps and cascade completeness.
How this NIST control supports HIPAA Security Rule expectations.
Disable promptly; delete/remove per retention rules. Disabled-but-recoverable may be acceptable short-term if securely controlled.
Eliminate them; they make clean revocation nearly impossible.
Define by risk — privileged and remote access should be hours, not days, for involuntary exits.
Related controls that commonly accompany AC-3(8).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.