AC-5 Access Control

Separation of Duties

High Risk Moderate Medium Cost

AC-5 requires separating duties of individuals to reduce the risk of malevolent activity without collusion, documenting separations of duties for organization-defined duties, and defining information system access authorizations that support those separations. In healthcare, this spans clinical IT administration, revenue-cycle controls, and privacy-sensitive functions such as audit-log access and disclosure management.

Control Objective

Prevent any one person from controlling an entire sensitive process end-to-end — especially where fraud, cover-ups, or undetected ePHI misuse could occur.

Implementation Guidance

  1. Identify high-risk duty pairs: access requestor vs approver; EHR security admin vs clinical end-user; claim submission vs payment posting; audit-log admin vs day-to-day chart access; backup operator vs restore approver for production PHI.
  2. Document SoD rules in policy and in system role design so conflicting roles cannot be assigned together (or require dual approval exception).
  3. Enforce separations in ticketing/IAM workflows — not only in org charts.
  4. For small practices where one person wears many hats, use compensating controls: secondary review, owner sign-off, increased logging, and periodic third-party spot checks.
  5. Review SoD conflicts quarterly from IdP/EHR role extracts.
  6. Apply dual control for destructive or irreversible actions (mass disclosure exports, privilege grants, production data restores).
  7. Train managers that 'temporary' combined access for go-lives still needs an end date and monitoring.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

IT admin who can also clear their own audit trail

If the same engineer administers the EHR and can delete security logs, misconduct can be hidden. AC-5 separates security-log administration from routine EHR admin, or requires dual custody for log retention settings.

Billing manager creates and pays vendors

In a small clinic RCM team, one manager both sets up payees and releases payments. SoD splits vendor master changes from payment approval, reducing embezzlement risk that often accompanies weak financial + EHR access governance.

Access approver approving their own elevation

A supervisor submits and approves their own privileged EHR access request. AC-5 workflow blocks self-approval and routes to a peer or compliance officer.

Best Practices

  • Maintain an SoD conflict matrix (role A conflicts with role B).
  • Encode conflicts in IAM where the tool supports it; otherwise review extracts.
  • Use dual control for break-glass privilege grants lasting more than a few hours.
  • Document compensating controls honestly for micro-practices.
  • Include BA staff who operate inside your systems in SoD thinking.
  • Revisit SoD after mergers when people inherit multiple legacy roles.

Common Gaps & Violations

  • Same person is EHR security officer and unrestricted clinical user on production.
  • Self-approval of access requests in the ticketing system.
  • 'Emergency' combined roles that become permanent.
  • No SoD analysis for revenue-cycle applications that touch claims and remits.
  • Developers with production deploy rights and production data access with no peer review.

Required Documentation

  • Separation of duties policy and conflict matrix
  • Role design standards showing conflicting roles
  • Workflow screenshots preventing self-approval
  • Compensating control descriptions for small teams
  • Quarterly SoD conflict review results

How to Test & Validate

  1. Extract users holding two conflicting roles; investigate each hit.
  2. Attempt self-approval of an access request in a test workflow; confirm block.
  3. Walk through a privileged change requiring dual control end-to-end.
  4. Interview small-clinic leadership on compensating reviews.
  5. Sample financial and clinical admin duties for concentration risk.

Audit Considerations

Auditors look for a written conflict matrix and evidence it is enforced. 'We're too small for SoD' is acceptable only with documented compensating controls and monitoring — not as a blank exemption.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — authorization and supervision support dividing duties that affect ePHI access.
  • 164.308(a)(1)(ii)(B) Risk Management — SoD is a common risk treatment for fraud and insider threat.
  • 164.312(a)(1) Access Control — technical access authorizations should reflect separated duties.
  • 164.308(a)(4) Information Access Management — clearinghouses and access isolation concepts align with preventing concentrated control.

Compliance Tips

  • Start SoD with the top 10 conflict pairs that matter for ePHI and money — do not boil the ocean.
  • Put SoD checks into the access-review packet managers already sign.
  • For solo IT shops, engage an external reviewer quarterly as a compensating control.

Frequently Asked Questions

Can a small practice meet AC-5?

Yes, through documented compensating controls — secondary review, logging, and limited standing privilege — when full staff separation is impossible.

Is SoD only a finance control?

No. In healthcare it equally applies to access administration, audit logging, disclosures, and production changes affecting ePHI.

How does AC-5 relate to AC-6?

AC-5 splits conflicting duties across people; AC-6 limits how much power each duty/role holds.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-5 Separation of Duties
  • HIPAA Security Rule §§ 164.308(a)(1), 164.308(a)(3)–(4), 164.312(a)
  • Related controls: AC-2, AC-3, AC-6, AU-6, AU-9

Need Help Implementing AC-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.