AC-6(9) Access Control

AC-6(9) Log Use of Privileged Functions

High Risk Moderate Medium Cost

AC-6(9) requires logging the execution of privileged functions. Healthcare must capture who changed EHR roles, disabled MFA, altered audit settings, ran privileged SQL, or used break-glass. Logs feed AU-6 reviews, incident response, and OCR investigations. If privileged actions leave no trail, least privilege cannot be proven or reconstructed after an event.

Control Objective

Record privileged function executions on systems protecting or storing ePHI with enough detail to attribute, investigate, and review administrative activity.

Implementation Guidance

  1. Define privileged functions to log per system (role changes, auth policy, key ops, admin logons, privileged SQL, firewall changes).
  2. Enable native admin auditing and forward to SIEM with integrity protections (AU-9).
  3. Include PAM/session recordings for highest-risk platforms where feasible.
  4. Synchronize time (NTP) so privileged events correlate across EHR, IdP, and network.
  5. Alert on high-risk privileged actions (audit disable, mass role grant, VIP break-glass).
  6. Retain privileged logs per policy and legal requirements.
  7. Review privileged logs on a defined cadence (pairs with AU-6).
  8. Test that logging survives admin attempts to stop the agent — alert on logging failures.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR role grant logged

Security admin adds a user to 'Health Information Export'; SIEM records actor, target, and timestamp; weekly review spots an unapproved grant.

MFA policy change alert

IdP Conditional Access weakened; real-time alert pages the SOC — AC-6(9) logging enables immediate IR.

Privileged SQL select on VIP table

DBA privileged query is logged via database audit; privacy investigates after SIEM correlation with VIP list.

Best Practices

  • Centralize privileged logs in SIEM.
  • Alert on Critical privileged actions.
  • Protect log integrity.
  • Cover cloud admin planes too.
  • Review cadence with evidence.
  • Include PAM recordings for vendors.

Common Gaps & Violations

  • Privileged admin actions not audited in EHR.
  • Logs only on disk of the same server admins can wipe.
  • No alerts for audit-policy disable.
  • Cloud Owner activity not logged to customer SIEM.
  • Reviews never performed despite logging being 'on.'

Required Documentation

  • Privileged function logging standard
  • List of privileged events logged per system
  • SIEM forwarding / retention evidence
  • Alert use cases for privileged actions
  • Sample review records of privileged logs

How to Test & Validate

  1. Execute a controlled privileged action; confirm log fields (who/what/when/where).
  2. Verify logs arrive in SIEM within expected latency.
  3. Attempt (in test) to disable auditing; confirm alert.
  4. Sample cloud privileged activity logs.
  5. Confirm review evidence for the last period.

Audit Considerations

Assessors ask for proof of a specific admin change. If you cannot produce privileged-function logs, AC-6(9) and HIPAA audit controls both look weak.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — record and examine activity in systems with ePHI; privileged actions are priority.
  • 164.308(a)(1) Risk Management — detect misuse of admin rights.
  • 164.312(a)(1) Access Control — accountability for administrative access.
  • 164.316 Documentation — retain audit documentation appropriately.

Compliance Tips

  • Make 'disable audit' a P1 alert with paging.
  • Map privileged log sources in the SSP audit appendix.
  • Pair AC-6(9) with AC-3(10) so break-glass is both allowed and logged.

Frequently Asked Questions

Is login logging enough?

No — log the privileged functions themselves (changes), not only successful admin authentication.

Do we need keystroke recording?

Not always; event-level admin audit plus selective session recording for vendors often suffices.

How long to retain?

Follow your retention schedule and investigation needs; privileged logs often warrant longer retention than routine access logs.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-6(9)
  • Related: AU-2, AU-3, AU-6, AU-9, AC-6(1), AC-3(10)

Need Help Implementing AC-6(9)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.