AC-6(3) Access Control

AC-6(3) Network Access to Privileged Commands

Critical Risk Complex Medium Cost

AC-6(3) requires authorizing network access to organization-defined privileged commands only for organization-defined compelling operational needs, and documenting the rationale. Remote root/RDP/SSH/WinRM into ePHI servers from anywhere on the corporate LAN — or the internet — is a classic healthcare failure mode. Privileged commands should ride controlled admin networks, PAW/jump hosts, or PAM brokers.

Control Objective

Allow remote/network invocation of privileged commands on ePHI systems only where justified, documented, and constrained to approved paths and identities.

Implementation Guidance

  1. Inventory privileged remote channels: RDP, SSH, WinRM, vendor support tools, cloud consoles, EHR thick-client admin modes.
  2. Default-deny direct privileged admin from general user VLANs and the internet.
  3. Require PAM/jump host or VPN + MFA + admin VLAN for privileged remote work.
  4. Document business need for each allowed privileged network path.
  5. Time-box vendor remote privileged access; record sessions when feasible.
  6. Disable unused privileged listeners; alert on unexpected opens.
  7. Prefer just-in-time elevation over standing remote admin rights.
  8. Review privileged network access rules quarterly with network and security teams.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

DBA remote into ePHI SQL

DBAs cannot RDP from the wifi cafe VLAN; they must use a PAM broker on the admin segment with MFA and session logging.

OEM EHR remote support

Vendor privileged session is ticketed, brokered, and ends when the change window closes — no standing AnyDesk from the internet into production.

Cloud Owner console

Subscription Owner actions for the PHI project require Conditional Access from compliant PAWs — not personal phones on open Wi-Fi without controls.

Best Practices

  • Admin VLANs / PAWs for privileged work.
  • MFA + PAM for remote privileged commands.
  • Document rationale per path.
  • Session recording for vendors.
  • JIT over standing remote admin.
  • Alert on privileged listener exposure.

Common Gaps & Violations

  • Domain admin RDP open from all corporate subnets.
  • SSH root from the internet with password auth.
  • Standing vendor remote tools on EHR hosts.
  • No documentation of why privileged remote is allowed.
  • Cloud Owner usable from any geography without CA policies.

Required Documentation

  • Privileged network access standard
  • Inventory of privileged remote channels
  • Documented operational need per allowed path
  • PAM/jump-host architecture notes
  • Vendor remote privileged access procedure

How to Test & Validate

  1. Attempt privileged RDP/SSH from a standard user VLAN; confirm deny.
  2. Complete admin task via approved PAM path; confirm success and logs.
  3. Scan ePHI servers for unexpected privileged listeners.
  4. Review vendor remote sessions for ticket linkage and end times.
  5. Verify cloud privileged console Conditional Access policies.

Audit Considerations

Network diagrams and firewall rules showing who can reach admin ports on ePHI systems are primary evidence. Broad RDP exposure is a high-severity finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — control access to systems maintaining ePHI, including remote admin paths.
  • 164.312(e) Transmission Security — protect remote administrative sessions.
  • 164.308(a)(1) Risk Analysis — remote privileged access is a major threat vector.
  • 164.308(b) Business Associate — vendor remote privileged access needs contractual and technical controls.

Compliance Tips

  • Put 'no direct RDP to ePHI servers from user VLANs' in the secure configuration baseline.
  • Require a written operational-need blurb in every firewall exception for admin ports.
  • Align with AC-17 remote access and MA-4 remote maintenance.

Frequently Asked Questions

Does this ban all remote administration?

No — it requires authorization, compelling need, and documentation for network access to privileged commands.

Are cloud consoles 'network access'?

Treat them as privileged network command channels and constrain similarly.

What about out-of-band lights-out management?

Include iLO/iDRAC in the inventory; isolate and MFA-protect them.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(3)
  • Related: AC-17, MA-4, CM-7, SC-7, IA-2

Need Help Implementing AC-6(3)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.