PAW for AD admins
Identity engineers perform domain admin tasks only from PAWs that cannot open mail — phishing on their daily laptop cannot replay Tier-0 creds.
AC-6(4) requires providing separate processing domains for privileged functions and non-privileged work — via virtualization, dedicated machines, separate accounts/networks, or similar. Healthcare orgs implement this with privileged access workstations (PAWs), admin VDI pools, tiered AD models, and isolated cloud management subscriptions so browsing and charting malware cannot sit beside domain-admin sessions.
Isolate privileged administrative and security processing from everyday clinical and office processing to contain compromise and enforce least privilege.
How this control shows up in healthcare and HIPAA-covered environments.
Identity engineers perform domain admin tasks only from PAWs that cannot open mail — phishing on their daily laptop cannot replay Tier-0 creds.
DBA privileged SQL work occurs in a locked-down VDI pool with no copy-paste to personal OneDrive and no general web.
Break-glass and Owner actions for the ePHI landing zone use a management subscription distinct from developer sandboxes.
Assessors look for practical separation — not just policy. Screenshots of PAW pools, tier diagrams, and blocked paths from user VLANs carry weight.
How this NIST control supports HIPAA Security Rule expectations.
Hardened admin VDI can meet the intent if it truly separates privileged processing and blocks risky apps.
This enhancement targets privileged functions; clinical RBAC is separate. Focus on admin/security processing.
SC-2/SC-3 address application/security function isolation; AC-6(4) focuses on privilege-driven processing domain separation for users performing privileged work.
Related controls that commonly accompany AC-6(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.