Clerk cannot open security workbench
Front-desk role has no path — UI or API — to edit access roles; attempts return authorization errors logged for review.
AC-6(10) requires prohibiting non-privileged users from executing privileged functions to include disabling, circumventing, or altering security safeguards. This is the enforcement twin of least privilege: a registration clerk must not run EHR security tools, a nurse must not disable EDR, and a standard cloud user must not elevate to modify IAM policies. Technical denial — not only policy — is required.
Ensure non-privileged users cannot execute, disable, or bypass privileged security and administrative functions on systems that create, receive, maintain, or transmit ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Front-desk role has no path — UI or API — to edit access roles; attempts return authorization errors logged for review.
Standard clinical Windows image blocks agent stop/uninstall; tamper event alerts SOC.
Only Privileged Role Administrators assign elevated directory roles; self-service elevation is off except through governed PIM packages.
Live negative testing is persuasive evidence. Policy statements without technical denial fail AC-6(10). Assessors may ask staff to demonstrate a denied privileged action.
How this NIST control supports HIPAA Security Rule expectations.
Closely related. AC-3(1) emphasizes restricted access to privileged functions; AC-6(10) emphasizes prohibiting non-privileged users from executing them as a least-privilege enhancement.
Use JIT privileged accounts (AC-6(5)) rather than making their daily ID privileged.
Yes — ensure patients and standard users cannot invoke admin or safeguard-disable functions via the app.
Related controls that commonly accompany AC-6(10).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.