AC-6(6) Access Control

AC-6(6) Privileged Access by Non-Organizational Users

Critical Risk Complex Medium Cost

AC-6(6) requires prohibiting privileged access to the system by non-organizational users — or, where unavoidable, applying organization-defined alternative controls. EHR OEMs, cloud operators, biomed vendors, and offshore BA admins often need elevated rights. Treat that as exceptional: named users, BAAs, time-boxed access, monitored sessions, and no standing domain admin for outsiders.

Control Objective

Prevent standing privileged access by outsiders to ePHI systems, allowing only exceptional, controlled, and monitored privileged vendor/BA access when operationally required.

Implementation Guidance

  1. Default deny privileged roles for any non-employee identity source.
  2. When vendors need privilege, require BAA/contract, named accounts, MFA, and ticketed windows.
  3. Prefer supervised or recorded sessions (MA-5/MA-4) over unattended privilege.
  4. Use PAM check-out credentials that expire automatically.
  5. Segment vendor admin into jump environments — not full corporate Tier-0.
  6. Ban vendor accounts in Domain Admins / global cloud Owner unless extraordinary risk acceptance.
  7. Review non-org privileged access weekly; remove stale rights.
  8. Document alternative controls when a SaaS provider’s privileged backend access is inherent (transparency reports, SOC reports, contractual limits).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR vendor weekend patch

OEM engineers receive JIT privileged EHR accounts Friday 18:00–Sunday 18:00 with session recording; accounts disable automatically afterward.

Offshore RCM admin

BA staff get application roles for claim edits, not infrastructure admin on the hospital AD — AC-6(6) keeps privilege inside the BA’s own scoped system.

Cloud hyperscaler operations

Customer cannot eliminate provider privileged ops; alternative controls include customer-managed keys, activity logs, and contractual security commitments documented in the SSP.

Best Practices

  • Default deny outsider privilege.
  • JIT + MFA + monitoring when required.
  • Named vendor users only.
  • No Tier-0 for vendors without extreme justification.
  • Weekly stale-access cleanup.
  • Document SaaS inherent privilege alternatives.

Common Gaps & Violations

  • Standing vendor domain admin.
  • Shared 'VendorSupport' privileged login.
  • Unmonitored Always-On remote support.
  • BA staff given hospital Global Administrator.
  • No inventory of non-org privileged users.

Required Documentation

  • Policy on non-organizational privileged access
  • Inventory of vendor/BA privileged accounts
  • JIT/PAM vendor access procedure
  • BAA references for privileged vendors
  • Risk acceptance for inherent SaaS privilege (if any)

How to Test & Validate

  1. Query privileged groups for external/guest identities.
  2. Sample vendor privileged access for ticket, MFA, and end date.
  3. Confirm session monitoring for remote OEM admin.
  4. Review stale non-org accounts still privileged.
  5. Verify BA staff lack hospital Tier-0 rights.

Audit Considerations

Third-party privileged access is a top OCR and assessor focus. Standing vendor admin without monitoring is a severe finding even when a BAA exists.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — vendors with ePHI access need BAAs and safeguards.
  • 164.314 Organizational Requirements — satisfactory assurances include operational privilege limits.
  • 164.312(a)(1) Access Control — limit privileged access regardless of employment status.
  • 164.308(a)(1) Risk Analysis — third-party privilege is a distinct risk to analyze.

Compliance Tips

  • Put non-org privileged access on the weekly IAM review agenda.
  • Require vendors to name individuals — refuse shared IDs.
  • For SaaS, capture customer-responsibility vs provider-privilege in the SSP.

Frequently Asked Questions

Does AC-6(6) ban all vendor access?

It prohibits privileged access by default; non-privileged BA access may still be appropriate with controls.

What if the EHR is fully vendor-hosted?

Document inherent provider privilege and your compensating customer controls (CMK, logging, access reviews).

Are students non-organizational?

Often yes for access policy purposes — avoid privileged rights; use supervised clinical roles only.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(6)
  • Related: AC-6(5), MA-5, MA-4, SA-9, PS-7

Need Help Implementing AC-6(6)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.