DBA remote into ePHI SQL
DBAs cannot RDP from the wifi cafe VLAN; they must use a PAM broker on the admin segment with MFA and session logging.
AC-6(3) requires authorizing network access to organization-defined privileged commands only for organization-defined compelling operational needs, and documenting the rationale. Remote root/RDP/SSH/WinRM into ePHI servers from anywhere on the corporate LAN — or the internet — is a classic healthcare failure mode. Privileged commands should ride controlled admin networks, PAW/jump hosts, or PAM brokers.
Allow remote/network invocation of privileged commands on ePHI systems only where justified, documented, and constrained to approved paths and identities.
How this control shows up in healthcare and HIPAA-covered environments.
DBAs cannot RDP from the wifi cafe VLAN; they must use a PAM broker on the admin segment with MFA and session logging.
Vendor privileged session is ticketed, brokered, and ends when the change window closes — no standing AnyDesk from the internet into production.
Subscription Owner actions for the PHI project require Conditional Access from compliant PAWs — not personal phones on open Wi-Fi without controls.
Network diagrams and firewall rules showing who can reach admin ports on ePHI systems are primary evidence. Broad RDP exposure is a high-severity finding.
How this NIST control supports HIPAA Security Rule expectations.
No — it requires authorization, compelling need, and documentation for network access to privileged commands.
Treat them as privileged network command channels and constrain similarly.
Include iLO/iDRAC in the inventory; isolate and MFA-protect them.
Related controls that commonly accompany AC-6(3).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.