AC-6(7) Access Control

AC-6(7) Review of User Privileges

High Risk Moderate Medium Cost

AC-6(7) requires reviewing the privileges assigned to users of organization-defined roles on a defined frequency to validate continuing need. Healthcare privilege creep — float nurses who keep ICU rights, IT staff who accumulate every EHR module, vendors who never lose admin — is a leading audit finding. Reviews must produce remediations, not just screenshots.

Control Objective

Validate on a defined cadence that each user’s privileges on ePHI and privileged systems remain necessary for current duties, and revoke what is not.

Implementation Guidance

  1. Define review frequency by risk: privileged monthly; standard ePHI roles quarterly; low-risk annually.
  2. Include managers/system owners as attestors with IAM-provided entitlement lists.
  3. Review effective privileges, not only primary role names (nested groups matter).
  4. Track remediation tickets to closure for revoked rights.
  5. Cover non-employees and service accounts.
  6. Escalate unreviewed items past due dates.
  7. Feed joiner/mover/leaver quality metrics from review findings.
  8. Retain attestation evidence for audit sampling.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Quarterly EHR role attestation

Clinic managers attest their staff; three ex-employees still listed are revoked same week — review caught JML failures.

Monthly privileged AD review

Security reviews Domain Admins and EHR security roles; two contractors past end date are removed.

Warehouse entitlement creep

Analyst keeps PHI warehouse admin after moving to a non-analytics job; quarterly review strips the privilege.

Best Practices

  • Risk-based review cadence.
  • Manager attestation with complete entitlement views.
  • Remediate, do not only attest.
  • Include service and vendor accounts.
  • Measure overdue reviews.
  • Sample-validate attestations for rubber-stamping.

Common Gaps & Violations

  • Annual paper sign-off with no removals ever.
  • Reviews of role names only, missing nested rights.
  • Privileged accounts excluded 'because IT knows.'
  • No evidence retained.
  • Attestors approve blank or incomplete lists.

Required Documentation

  • Privilege review / access certification procedure
  • Review schedules by system/risk tier
  • Completed attestation campaigns and metrics
  • Remediation ticket samples
  • Scope definition (who/what is reviewed)

How to Test & Validate

  1. Select a recent campaign; verify completion rate and overdue handling.
  2. Sample attested users against HR job titles for mismatches.
  3. Confirm remediations closed for revoked privileges.
  4. Check privileged review occurred within policy frequency.
  5. Verify vendor/service accounts appeared in scope.

Audit Considerations

Assessors sample access reviews for completeness and actual privilege removal. Rubber-stamp campaigns without deltas are weak evidence for AC-6(7).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(4) Information Access Management — periodic review supports appropriate access.
  • 164.308(a)(3)(ii)(B) Workforce Clearance — continuing appropriateness of access.
  • 164.312(a)(1) Access Control — maintain authorized-only access over time.
  • 164.308(a)(8) Evaluation — evaluations often include access appropriateness testing.

Compliance Tips

  • Automate campaign launches from the IAM tool; avoid spreadsheet-only reviews for large orgs.
  • Require 'last login' and 'job title' columns on attestor views.
  • Report removal counts to leadership to prove reviews have teeth.

Frequently Asked Questions

Is user access review the same as vulnerability review?

No. AC-6(7) is about assigned privileges/entitlements for users and roles.

Who should attest?

Typically the user’s manager or application owner who understands job need — not only central IT.

How fast must remediations close?

Define SLAs (e.g., 7 days for High privilege removals) and track them.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(7)
  • Related: AC-2, AC-3(8), AC-6, PS-5, IA-4

Need Help Implementing AC-6(7)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.