AC-6(5) Access Control

AC-6(5) Privileged Accounts

Critical Risk Moderate Medium Cost

AC-6(5) requires restricting privileged accounts on the system to organization-defined personnel or roles. Healthcare needs named, inventory-managed privileged accounts for EHR security, domain admin, cloud Owner, database sa-equivalents, and network admins — with MFA, vaulting, and lifecycle controls. Shared 'EHRAdmin' passwords violate both least privilege and unique user identification.

Control Objective

Limit privileged accounts to the minimum set of authorized people and roles, each with a managed privileged identity separate from routine access.

Implementation Guidance

  1. Inventory all privileged accounts across AD, Entra, EHR, databases, network, and cloud.
  2. Eliminate shared privileged IDs; assign individual accountability.
  3. Issue dedicated privileged accounts distinct from daily UPNs.
  4. Vault passwords/keys; rotate on schedule and after use for break-glass.
  5. Enforce MFA/phishing-resistant auth for privileged accounts.
  6. Disable interactive use of service accounts; monitor exceptions.
  7. Recertify privileged account need monthly.
  8. Alert on new privileged account creation outside the IAM process.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Named EHR security admins

Three engineers receive jsmith-ea style privileged EHR accounts; the old shared 'SecAdmin' ID is disabled and password vaulted historically for audit.

Cloud break-glass

Two emergency Owner accounts exist in the vault, MFA-protected, monitored, and tested quarterly — not used for daily Terraform runs.

SQL sa disabled

Application uses managed service identities; human DBAs use personal privileged logins via PAM — sa is disabled.

Best Practices

  • Named privileged accounts only.
  • Dual account model.
  • Vault + rotate.
  • MFA mandatory.
  • Monthly privileged account recert.
  • Monitor creation of new privileged IDs.

Common Gaps & Violations

  • Shared EHR admin password on a wiki.
  • Daily account in Domain Admins.
  • Orphaned privileged accounts for departed staff.
  • Service accounts with interactive logon and mailbox.
  • Unlimited cloud Owner assignments to contractors.

Required Documentation

  • Privileged account standard
  • Current privileged account inventory
  • Dual-account / naming convention guide
  • Vault and rotation procedure
  • Recertification records

How to Test & Validate

  1. Export privileged group memberships; confirm each map to authorized personnel.
  2. Search for shared/generic privileged account names still enabled.
  3. Verify MFA registration on privileged accounts.
  4. Confirm departed employees have no privileged IDs active.
  5. Review service accounts for interactive logon rights.

Audit Considerations

Privileged account inventories and MFA evidence are standard request items. Shared admin IDs are nearly automatic findings under HIPAA unique user ID expectations.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(i) Unique User Identification — privileged access must be attributable to individuals.
  • 164.312(a)(1) Access Control — limit privileged access.
  • 164.308(a)(3) Workforce Security — authorize workforce for elevated duties.
  • 164.312(d) Person or Entity Authentication — strong auth for privileged accounts.

Compliance Tips

  • Publish a privileged account naming standard (*-ea, *-adm) so reviews are easy.
  • Feed privileged inventory into SIEM asset context.
  • Kill generic admin IDs before the next assessment cycle.

Frequently Asked Questions

Are emergency accounts allowed?

Yes if few, vaulted, MFA-protected, monitored, and rarely used with after-action review.

Can one person have multiple privileged accounts?

Yes across systems; still keep them separate from the daily productivity account.

Do application service accounts count?

Yes — inventory, owner, minimal rights, no interactive use.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(5)
  • Related: AC-2, AC-6(2), IA-2, IA-5, AU-2

Need Help Implementing AC-6(5)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.