Bulk research extract
Analyst requests 50,000-patient file; data steward plus privacy officer must both approve before the job runs.
AC-5(1) enhances AC-5 by focusing on dual authorization for critical functions. Require two authorized persons for critical conflicting or high-impact functions (security-admin grants, bulk ePHI export, break-glass enablement). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Enforce dual authorization for organization-defined critical functions that could broadly expose or alter ePHI access.
How this control shows up in healthcare and HIPAA-covered environments.
Analyst requests 50,000-patient file; data steward plus privacy officer must both approve before the job runs.
IT builds a role; security leadership must approve assignment before it activates — one admin cannot mint peers alone.
Turning on enterprise break-glass requires dual authorization from security and clinical informatics on-call.
Assessors look for operating evidence of Dual Authorization for Critical Functions on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-5(1).
How this NIST control supports HIPAA Security Rule expectations.
No — MFA proves one user; dual authorization requires two people for the action.
Use privacy officer or practice admin as second approver for Critical actions.
Only if the system blocks until second approval is recorded.
Related controls that commonly accompany AC-5(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.