Control Objective
Prevent any one person from controlling an entire sensitive process end-to-end — especially where fraud, cover-ups, or undetected ePHI misuse could occur.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
IT admin who can also clear their own audit trail
If the same engineer administers the EHR and can delete security logs, misconduct can be hidden. AC-5 separates security-log administration from routine EHR admin, or requires dual custody for log retention settings.
Billing manager creates and pays vendors
In a small clinic RCM team, one manager both sets up payees and releases payments. SoD splits vendor master changes from payment approval, reducing embezzlement risk that often accompanies weak financial + EHR access governance.
Access approver approving their own elevation
A supervisor submits and approves their own privileged EHR access request. AC-5 workflow blocks self-approval and routes to a peer or compliance officer.
Audit Considerations
Auditors look for a written conflict matrix and evidence it is enforced. 'We're too small for SoD' is acceptable only with documented compensating controls and monitoring — not as a blank exemption.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.308(a)(3) Workforce Security — authorization and supervision support dividing duties that affect ePHI access.
- 164.308(a)(1)(ii)(B) Risk Management — SoD is a common risk treatment for fraud and insider threat.
- 164.312(a)(1) Access Control — technical access authorizations should reflect separated duties.
- 164.308(a)(4) Information Access Management — clearinghouses and access isolation concepts align with preventing concentrated control.