AC-3(8) Access Control

AC-3(8) Revocation of Access Authorizations

Critical Risk Moderate Medium Cost

AC-3(8) requires enforcing the revocation of access authorizations resulting from changes to security attributes of objects or subjects (e.g., role changes, clearance loss, employment end) within organization-defined time periods. Healthcare breaches frequently involve terminated staff or vendors whose EHR, VPN, and badge rights lingered. Revocation must be timely, complete across systems, and verified.

Control Objective

Withdraw ePHI access authorizations quickly and completely when subject or object security attributes change so former rights cannot be exercised beyond policy time limits.

Implementation Guidance

  1. Define revocation SLAs (e.g., involuntary termination: disable within hours; routine role change: same business day).
  2. Trigger revocation from HRIS events, contract end dates, and security incidents.
  3. Cascade disables across IdP, EHR, email, VPN, cloud apps, and remote support tools.
  4. Revoke object-level shares when documents are reclassified or ownership moves.
  5. Include non-employees: students, locums, BA technicians.
  6. Verify with post-revocation login attempts and access recertification samples.
  7. Retain evidence of who revoked what and when for audits.
  8. Pair with badge/physical access revocation (PE family) for holistic cut-off.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nurse terminated mid-shift

HR marks involuntary exit; IdP disable fires within the hour; EHR session tokens fail refresh; VPN cert revoked — AC-3(8) meets the aggressive SLA.

Contractor engagement ends Friday

Vendor accounts auto-expire Friday 17:00; Monday review confirms no residual PACS admin role remained.

Patient chart sealed after legal hold attribute change

Security attributes on the object change; prior discretionary Care Team views that conflict with the new seal are revoked automatically where the EHR supports it.

Best Practices

  • Automate IdP-centric revocation where possible.
  • Publish numeric SLAs by event type.
  • Cover SaaS and clinical specialty systems, not only AD.
  • Verify revocation, do not only ticket it.
  • Include API and service accounts tied to people.
  • Run weekly orphaned-access reports.

Common Gaps & Violations

  • EHR access active weeks after termination.
  • VPN certs never revoked.
  • Role change adds new access but never removes old.
  • Vendor shared accounts survive staff turnover.
  • No SLA — 'as soon as possible' with no measurement.

Required Documentation

  • Access revocation procedure and SLAs
  • JML workflow including revoke steps
  • System cascade checklist (IdP → EHR → VPN…)
  • Sample termination evidence packs
  • Metrics: time-to-revoke reports

How to Test & Validate

  1. Sample recent terminations: compare HR end timestamp to IdP/EHR disable times.
  2. Attempt login with a known revoked test account; confirm fail.
  3. Sample movers: prior department roles removed.
  4. Review vendor account expirations.
  5. Confirm physical badge disable aligned when applicable.

Audit Considerations

Comparing termination lists to active EHR users is a standard HIPAA assessment test. AC-3(8) evidence is the disable timestamps and cascade completeness.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3)(ii)(C) Termination Procedures — terminate access when employment ends.
  • 164.308(a)(4)(ii)(C) Access Establishment and Modification — modify access as roles change; includes revocation.
  • 164.312(a)(1) Access Control — only authorized persons retain access.
  • 164.308(a)(1) Risk Management — lingering access is a known high risk.

Compliance Tips

  • Measure median and max time-to-revoke monthly for leadership.
  • Put emergency revoke hotline/process for security incidents (stolen credentials).
  • Include cloud apps in the cascade checklist — they are often missed.

Frequently Asked Questions

Is disable enough, or must we delete?

Disable promptly; delete/remove per retention rules. Disabled-but-recoverable may be acceptable short-term if securely controlled.

What about shared department accounts?

Eliminate them; they make clean revocation nearly impossible.

How fast is fast enough?

Define by risk — privileged and remote access should be hours, not days, for involuntary exits.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-3(8)
  • Related: AC-2, PS-4, PS-5, IA-4, AC-6(7)

Need Help Implementing AC-3(8)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.