AC-5(1) Access Control

Dual Authorization for Critical Functions

Critical Risk Complex Medium Cost

AC-5(1) enhances AC-5 by focusing on dual authorization for critical functions. Require two authorized persons for critical conflicting or high-impact functions (security-admin grants, bulk ePHI export, break-glass enablement). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Enforce dual authorization for organization-defined critical functions that could broadly expose or alter ePHI access.

Implementation Guidance

  1. List critical functions needing dual authorization.
  2. Enforce two distinct identities in workflow tools.
  3. Ban self-approval and shared approver accounts.
  4. Time-box dual-authorized privileges.
  5. Log both authorizations with rationale.
  6. Cover bulk export, security-admin grants, break-glass enable.
  7. Define emergency path with after-action review.
  8. Test fail-closed without second approver.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Bulk research extract

Analyst requests 50,000-patient file; data steward plus privacy officer must both approve before the job runs.

Security-admin role grant

IT builds a role; security leadership must approve assignment before it activates — one admin cannot mint peers alone.

Break-glass master enable

Turning on enterprise break-glass requires dual authorization from security and clinical informatics on-call.

Best Practices

  • Tie AC-5(1) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims dual authorization for critical functions but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Dual Authorization for Critical Functions (AC-5(1))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to dual authorization for critical functions; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Dual Authorization for Critical Functions on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-5(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — authorization and supervision; separation reduces insider risk.
  • 164.308(a)(4) Information Access Management — isolate duties for access establishment/modification.
  • 164.312(a)(1) Access Control — dual control for privileged actions.
  • 164.312(b) Audit Controls — dual-auth and separation events should be attributable.

Compliance Tips

  • List AC-5(1) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Same as MFA?

No — MFA proves one user; dual authorization requires two people for the action.

Small clinic staffing?

Use privacy officer or practice admin as second approver for Critical actions.

Email FYI enough?

Only if the system blocks until second approval is recorded.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-5(1)
  • Related controls: AC-5, AC-3(2), AC-6, AU-2

Need Help Implementing AC-5(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.