Analyst phished while not elevated
SOC analyst reads mail on a standard account; stolen session cannot modify firewall rules. Admin tasks require a separate PAM login.
AC-6(2) requires that users access nonsecurity functions using non-privileged accounts or roles. Clinicians, billers, and even IT staff doing email or ticket triage should not operate as local administrators or EHR security admins for daily work. Malware and phishing that hit a privileged session gain instant ePHI and infrastructure reach.
Ensure day-to-day nonsecurity work on healthcare systems runs under non-privileged identities, with privileged roles used only for explicit administrative tasks.
How this control shows up in healthcare and HIPAA-covered environments.
SOC analyst reads mail on a standard account; stolen session cannot modify firewall rules. Admin tasks require a separate PAM login.
Providers chart without local admin; medical device drivers deploy via SCCM — ransomware cannot easily disable EDR.
Supervisor manages denials using a billing role only; security workbench is not attached to that daily account.
Endpoint local admin sprawl and shared privileged daily use are common healthcare findings. AC-6(2) is evidenced by account design and workstation configs, not policy alone.
How this NIST control supports HIPAA Security Rule expectations.
Routine clinical documentation, email, browsing, ticketing, and similar work that does not administer security controls.
Prefer dedicated privileged workstations or VDI with no email; if local admin is needed, isolate from ePHI and production creds.
No — it bans using them for ordinary nonsecurity tasks.
Related controls that commonly accompany AC-6(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.