AC-7(1) Access Control

Automatic Account Lock

High Risk Easy Low Cost

AC-7(1) enhances AC-7 by focusing on automatic account lock. Automatically lock accounts after organization-defined consecutive unsuccessful logons on EHR, VPN, email, and admin consoles. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Enforce automatic account lock after a defined number of consecutive unsuccessful logon attempts to ePHI systems.

Implementation Guidance

  1. Set consecutive failure thresholds by account type.
  2. Enable automatic lock on EHR, VPN, email, admin consoles.
  3. Stricter thresholds for privileged accounts.
  4. Define unlock identity-proofing procedures.
  5. Alert SOC on lock bursts (spray attacks).
  6. Align with AC-7 base unsuccessful logon policy.
  7. Test lock behavior after IdP changes.
  8. Document exceptions (service accounts) carefully.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR password spray stopped

After five failures, clinician account locks pending helpdesk identity proofing.

VPN admin faster lock

Privileged VPN admin locks after fewer attempts than standard users.

Night clinic workstation

Failed guesses on a nursing station lock the account rather than allowing endless retries against ePHI apps.

Best Practices

  • Tie AC-7(1) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims automatic account lock but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Automatic Account Lock (AC-7(1))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to automatic account lock; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Automatic Account Lock on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — unique user identification and emergency access procedures supported by lockout hygiene.
  • 164.312(d) Person or Entity Authentication — protect authentication mechanisms from online guessing.
  • 164.308(a)(1) Risk Management — credential stuffing against clinical accounts is a known threat.
  • 164.312(a)(2)(iv) Encryption/Decryption (mobile) — wipe supports device ePHI protection when paired with AC-19.

Compliance Tips

  • List AC-7(1) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

How many attempts?

Define by risk; privileged accounts often stricter than standard clinical users.

Lock vs delay?

Account lock is the enhancement; combine with progressive delays if useful.

Helpdesk unlock proofing?

Require identity proofing to avoid social-engineering unlocks.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-7(1)
  • Related controls: AC-7, AC-2, AU-2, IA-5

Need Help Implementing AC-7(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.