AC-6(2) Access Control

AC-6(2) Non-Privileged Access for Nonsecurity Functions

High Risk Moderate Medium Cost

AC-6(2) requires that users access nonsecurity functions using non-privileged accounts or roles. Clinicians, billers, and even IT staff doing email or ticket triage should not operate as local administrators or EHR security admins for daily work. Malware and phishing that hit a privileged session gain instant ePHI and infrastructure reach.

Control Objective

Ensure day-to-day nonsecurity work on healthcare systems runs under non-privileged identities, with privileged roles used only for explicit administrative tasks.

Implementation Guidance

  1. Issue standard user accounts without local admin or domain privilege for all workforce.
  2. Give IT dual accounts: daily UPN plus separate admin account (AC-6(5)).
  3. Remove local admin from clinical workstations via GPO/MDM; use LAPS/EPM for elevations.
  4. Block EHR security and cloud Owner roles on daily identities.
  5. Restrict software install rights; package clinical apps centrally.
  6. Monitor for privileged group membership on accounts that also do email/web browsing.
  7. Train staff why 'run as admin always' is banned.
  8. Exception list for rare specialized devices with compensating controls.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Analyst phished while not elevated

SOC analyst reads mail on a standard account; stolen session cannot modify firewall rules. Admin tasks require a separate PAM login.

Physician workstation lockdown

Providers chart without local admin; medical device drivers deploy via SCCM — ransomware cannot easily disable EDR.

Billing supervisor denied EHR security role

Supervisor manages denials using a billing role only; security workbench is not attached to that daily account.

Best Practices

  • Dual accounts for privileged staff.
  • No standing local admin on endpoints.
  • PAM/JIT for elevation.
  • Package software instead of user installs.
  • Hunt for privileged + mailbox-enabled combo risks.
  • Document device exceptions tightly.

Common Gaps & Violations

  • Domain admins use the same account for email.
  • Nurses run as local admin 'so scanners work.'
  • EHR security role left on for convenience all day.
  • Developers as local admin on laptops with PHI extracts.
  • Break-glass domain admin used as daily login.

Required Documentation

  • Least privilege / non-privileged use standard
  • Dual-account procedure for IT/security
  • Endpoint local-admin removal baseline
  • Elevation (LAPS/PAM) process
  • Exception register

How to Test & Validate

  1. Sample clinical and IT endpoints for local admin membership.
  2. Confirm privileged AD groups are not mail-enabled daily accounts (or are tightly monitored).
  3. Verify EHR security roles are not assigned to routine clinical UPNs.
  4. Attempt software install as standard user; confirm deny/elevate prompt.
  5. Review exception list currency.

Audit Considerations

Endpoint local admin sprawl and shared privileged daily use are common healthcare findings. AC-6(2) is evidenced by account design and workstation configs, not policy alone.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit capabilities of users accessing systems with ePHI.
  • 164.308(a)(1) Risk Analysis — privileged malware path is a top risk.
  • 164.308(a)(5) Security Awareness — train on safe use of accounts.
  • 164.306 General rules — reasonable and appropriate safeguards include least privilege on endpoints.

Compliance Tips

  • Make dual-account enrollment part of IT onboarding day one.
  • Track % of workstations without standing local admin as a KPI.
  • Remove 'local admin for all providers' as a go-live leftover.

Frequently Asked Questions

What are nonsecurity functions?

Routine clinical documentation, email, browsing, ticketing, and similar work that does not administer security controls.

Can developers keep local admin?

Prefer dedicated privileged workstations or VDI with no email; if local admin is needed, isolate from ePHI and production creds.

Does this ban privileged roles entirely?

No — it bans using them for ordinary nonsecurity tasks.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(2)
  • Related: AC-6, AC-6(5), CM-7, SI-3, IA-2

Need Help Implementing AC-6(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.