Lost phone with clinical app
Repeated failed unlock triggers MDM selective wipe of containers holding offline ePHI.
AC-7(2) enhances AC-7 by focusing on purge or wipe mobile device. After repeated failed auth on mobile devices with ePHI (or MDM-managed clinical apps), purge/wipe per policy to protect offline charts and tokens. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Purge or wipe information on mobile devices after organization-defined consecutive unsuccessful logon attempts when ePHI may be present.
How this control shows up in healthcare and HIPAA-covered environments.
Repeated failed unlock triggers MDM selective wipe of containers holding offline ePHI.
Full wipe after threshold removes downloaded visit notes.
Failed PIN spam on BYOD wipes the corporate work profile only, preserving personal photos.
Assessors look for operating evidence of Purge or Wipe Mobile Device on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(2).
How this NIST control supports HIPAA Security Rule expectations.
Prefer selective wipe of work containers when BYOD; full wipe for corporate devices per policy.
Yes — mobile clinical apps often cache charts; wipe addresses that risk.
Tune thresholds and educate users; provide recovery via MDM.
Related controls that commonly accompany AC-7(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.