EHR vendor weekend patch
OEM engineers receive JIT privileged EHR accounts Friday 18:00–Sunday 18:00 with session recording; accounts disable automatically afterward.
AC-6(6) requires prohibiting privileged access to the system by non-organizational users — or, where unavoidable, applying organization-defined alternative controls. EHR OEMs, cloud operators, biomed vendors, and offshore BA admins often need elevated rights. Treat that as exceptional: named users, BAAs, time-boxed access, monitored sessions, and no standing domain admin for outsiders.
Prevent standing privileged access by outsiders to ePHI systems, allowing only exceptional, controlled, and monitored privileged vendor/BA access when operationally required.
How this control shows up in healthcare and HIPAA-covered environments.
OEM engineers receive JIT privileged EHR accounts Friday 18:00–Sunday 18:00 with session recording; accounts disable automatically afterward.
BA staff get application roles for claim edits, not infrastructure admin on the hospital AD — AC-6(6) keeps privilege inside the BA’s own scoped system.
Customer cannot eliminate provider privileged ops; alternative controls include customer-managed keys, activity logs, and contractual security commitments documented in the SSP.
Third-party privileged access is a top OCR and assessor focus. Standing vendor admin without monitoring is a severe finding even when a BAA exists.
How this NIST control supports HIPAA Security Rule expectations.
It prohibits privileged access by default; non-privileged BA access may still be appropriate with controls.
Document inherent provider privilege and your compensating customer controls (CMK, logging, access reviews).
Often yes for access policy purposes — avoid privileged rights; use supervised clinical roles only.
Related controls that commonly accompany AC-6(6).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.