Quarterly EHR role attestation
Clinic managers attest their staff; three ex-employees still listed are revoked same week — review caught JML failures.
AC-6(7) requires reviewing the privileges assigned to users of organization-defined roles on a defined frequency to validate continuing need. Healthcare privilege creep — float nurses who keep ICU rights, IT staff who accumulate every EHR module, vendors who never lose admin — is a leading audit finding. Reviews must produce remediations, not just screenshots.
Validate on a defined cadence that each user’s privileges on ePHI and privileged systems remain necessary for current duties, and revoke what is not.
How this control shows up in healthcare and HIPAA-covered environments.
Clinic managers attest their staff; three ex-employees still listed are revoked same week — review caught JML failures.
Security reviews Domain Admins and EHR security roles; two contractors past end date are removed.
Analyst keeps PHI warehouse admin after moving to a non-analytics job; quarterly review strips the privilege.
Assessors sample access reviews for completeness and actual privilege removal. Rubber-stamp campaigns without deltas are weak evidence for AC-6(7).
How this NIST control supports HIPAA Security Rule expectations.
No. AC-6(7) is about assigned privileges/entitlements for users and roles.
Typically the user’s manager or application owner who understands job need — not only central IT.
Define SLAs (e.g., 7 days for High privilege removals) and track them.
Related controls that commonly accompany AC-6(7).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.