Named EHR security admins
Three engineers receive jsmith-ea style privileged EHR accounts; the old shared 'SecAdmin' ID is disabled and password vaulted historically for audit.
AC-6(5) requires restricting privileged accounts on the system to organization-defined personnel or roles. Healthcare needs named, inventory-managed privileged accounts for EHR security, domain admin, cloud Owner, database sa-equivalents, and network admins — with MFA, vaulting, and lifecycle controls. Shared 'EHRAdmin' passwords violate both least privilege and unique user identification.
Limit privileged accounts to the minimum set of authorized people and roles, each with a managed privileged identity separate from routine access.
How this control shows up in healthcare and HIPAA-covered environments.
Three engineers receive jsmith-ea style privileged EHR accounts; the old shared 'SecAdmin' ID is disabled and password vaulted historically for audit.
Two emergency Owner accounts exist in the vault, MFA-protected, monitored, and tested quarterly — not used for daily Terraform runs.
Application uses managed service identities; human DBAs use personal privileged logins via PAM — sa is disabled.
Privileged account inventories and MFA evidence are standard request items. Shared admin IDs are nearly automatic findings under HIPAA unique user ID expectations.
How this NIST control supports HIPAA Security Rule expectations.
Yes if few, vaulted, MFA-protected, monitored, and rarely used with after-action review.
Yes across systems; still keep them separate from the daily productivity account.
Yes — inventory, owner, minimal rights, no interactive use.
Related controls that commonly accompany AC-6(5).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.