EHR password spray stopped
After five failures, clinician account locks pending helpdesk identity proofing.
AC-7(1) enhances AC-7 by focusing on automatic account lock. Automatically lock accounts after organization-defined consecutive unsuccessful logons on EHR, VPN, email, and admin consoles. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Enforce automatic account lock after a defined number of consecutive unsuccessful logon attempts to ePHI systems.
How this control shows up in healthcare and HIPAA-covered environments.
After five failures, clinician account locks pending helpdesk identity proofing.
Privileged VPN admin locks after fewer attempts than standard users.
Failed guesses on a nursing station lock the account rather than allowing endless retries against ePHI apps.
Assessors look for operating evidence of Automatic Account Lock on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(1).
How this NIST control supports HIPAA Security Rule expectations.
Define by risk; privileged accounts often stricter than standard clinical users.
Account lock is the enhancement; combine with progressive delays if useful.
Require identity proofing to avoid social-engineering unlocks.
Related controls that commonly accompany AC-7(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.