AC-6(4) Access Control

AC-6(4) Separate Processing Domains

High Risk Very Complex High Cost

AC-6(4) requires providing separate processing domains for privileged functions and non-privileged work — via virtualization, dedicated machines, separate accounts/networks, or similar. Healthcare orgs implement this with privileged access workstations (PAWs), admin VDI pools, tiered AD models, and isolated cloud management subscriptions so browsing and charting malware cannot sit beside domain-admin sessions.

Control Objective

Isolate privileged administrative and security processing from everyday clinical and office processing to contain compromise and enforce least privilege.

Implementation Guidance

  1. Define tiers: user productivity, EHR servers, identity/admin tier.
  2. Provide PAW or hardened admin VDI for Tier-0/1 privileged work; block email/web on those domains where feasible.
  3. Separate admin credentials and never reuse them on user workstations (AC-6(5)/AC-6(2)).
  4. Segment admin networks from clinical user VLANs (SC-7).
  5. Use separate cloud management identities/subscriptions for PHI production vs sandboxes.
  6. Prohibit privileged sessions on shared clinic kiosks.
  7. Document domain separation architecture in the SSP (PL-2).
  8. Pilot with domain controllers and EHR database admin before expanding.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

PAW for AD admins

Identity engineers perform domain admin tasks only from PAWs that cannot open mail — phishing on their daily laptop cannot replay Tier-0 creds.

Admin VDI for EHR DBAs

DBA privileged SQL work occurs in a locked-down VDI pool with no copy-paste to personal OneDrive and no general web.

Separate cloud mgmt plane

Break-glass and Owner actions for the ePHI landing zone use a management subscription distinct from developer sandboxes.

Best Practices

  • PAW/admin VDI for high tiers.
  • No co-mingling mail and Tier-0 admin.
  • Network segmentation by tier.
  • Separate cloud management plane.
  • Start with identity and EHR data tiers.
  • Visual architecture for auditors.

Common Gaps & Violations

  • Domain admin on the same laptop used for YouTube and email.
  • Privileged RDP from nurse workstations.
  • Single flat AD with no tiering.
  • Cloud Owner on personal devices.
  • 'Temporary' admin jump boxes that become permanent shared desktops with browsing.

Required Documentation

  • Privileged processing domain / PAW standard
  • Tier model architecture diagram
  • Admin VDI/PAW configuration baseline
  • Network segmentation evidence for admin tiers
  • Operational guide for which work belongs in which domain

How to Test & Validate

  1. Confirm privileged credentials fail or are blocked on standard user endpoints for Tier-0 targets.
  2. Verify PAW/admin VDI blocks unapproved apps (mail/web) per policy.
  3. Trace network paths: user VLAN should not reach admin ports directly.
  4. Interview admins: where do they perform privileged work?
  5. Review cloud Conditional Access for admin portals requiring compliant/privileged device.

Audit Considerations

Assessors look for practical separation — not just policy. Screenshots of PAW pools, tier diagrams, and blocked paths from user VLANs carry weight.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — technical mechanisms limiting privileged processing.
  • 164.308(a)(1) Risk Management — isolate high-impact admin risk.
  • 164.312(b) Audit Controls — privileged domains should produce clearer audit trails.
  • 164.306 Flexibility of approach — virtualization or dedicated hosts can both satisfy separation.

Compliance Tips

  • Do not boil the ocean: separate Tier-0 (identity) and EHR data admin first.
  • Ban installing EHR thick-client admin tools on random desktops.
  • Pair with AC-6(3) so separated domains are the only network path to privileged commands.

Frequently Asked Questions

Is VDI enough without PAWs?

Hardened admin VDI can meet the intent if it truly separates privileged processing and blocks risky apps.

Do clinicians need separate domains?

This enhancement targets privileged functions; clinical RBAC is separate. Focus on admin/security processing.

How does this relate to SC-2/SC-3?

SC-2/SC-3 address application/security function isolation; AC-6(4) focuses on privilege-driven processing domain separation for users performing privileged work.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(4)
  • Microsoft PAW / tiering guidance (informative)
  • Related: AC-6(2), AC-6(3), AC-6(5), SC-2, SC-7

Need Help Implementing AC-6(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.