EHR role grant logged
Security admin adds a user to 'Health Information Export'; SIEM records actor, target, and timestamp; weekly review spots an unapproved grant.
AC-6(9) requires logging the execution of privileged functions. Healthcare must capture who changed EHR roles, disabled MFA, altered audit settings, ran privileged SQL, or used break-glass. Logs feed AU-6 reviews, incident response, and OCR investigations. If privileged actions leave no trail, least privilege cannot be proven or reconstructed after an event.
Record privileged function executions on systems protecting or storing ePHI with enough detail to attribute, investigate, and review administrative activity.
How this control shows up in healthcare and HIPAA-covered environments.
Security admin adds a user to 'Health Information Export'; SIEM records actor, target, and timestamp; weekly review spots an unapproved grant.
IdP Conditional Access weakened; real-time alert pages the SOC — AC-6(9) logging enables immediate IR.
DBA privileged query is logged via database audit; privacy investigates after SIEM correlation with VIP list.
Assessors ask for proof of a specific admin change. If you cannot produce privileged-function logs, AC-6(9) and HIPAA audit controls both look weak.
How this NIST control supports HIPAA Security Rule expectations.
No — log the privileged functions themselves (changes), not only successful admin authentication.
Not always; event-level admin audit plus selective session recording for vendors often suffices.
Follow your retention schedule and investigation needs; privileged logs often warrant longer retention than routine access logs.
Related controls that commonly accompany AC-6(9).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.