AC-7(2) Access Control

Purge or Wipe Mobile Device

High Risk Moderate Medium Cost

AC-7(2) enhances AC-7 by focusing on purge or wipe mobile device. After repeated failed auth on mobile devices with ePHI (or MDM-managed clinical apps), purge/wipe per policy to protect offline charts and tokens. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Purge or wipe information on mobile devices after organization-defined consecutive unsuccessful logon attempts when ePHI may be present.

Implementation Guidance

  1. Inventory MDM-managed devices with ePHI apps.
  2. Configure purge/wipe after failed auth threshold.
  3. Prefer selective wipe for BYOD work profiles.
  4. Full wipe policy for corporate clinical tablets.
  5. Notify users and helpdesk on wipe events.
  6. Test wipe on lost-device tabletop.
  7. Exclude shared fixed workstations from mobile wipe logic.
  8. Coordinate with AC-19 mobile controls.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Lost phone with clinical app

Repeated failed unlock triggers MDM selective wipe of containers holding offline ePHI.

Stolen home-health tablet

Full wipe after threshold removes downloaded visit notes.

BYOD work profile purge

Failed PIN spam on BYOD wipes the corporate work profile only, preserving personal photos.

Best Practices

  • Tie AC-7(2) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims purge or wipe mobile device but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Purge or Wipe Mobile Device (AC-7(2))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to purge or wipe mobile device; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Purge or Wipe Mobile Device on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — unique user identification and emergency access procedures supported by lockout hygiene.
  • 164.312(d) Person or Entity Authentication — protect authentication mechanisms from online guessing.
  • 164.308(a)(1) Risk Management — credential stuffing against clinical accounts is a known threat.
  • 164.312(a)(2)(iv) Encryption/Decryption (mobile) — wipe supports device ePHI protection when paired with AC-19.

Compliance Tips

  • List AC-7(2) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Selective vs full wipe?

Prefer selective wipe of work containers when BYOD; full wipe for corporate devices per policy.

Offline ePHI concern?

Yes — mobile clinical apps often cache charts; wipe addresses that risk.

False wipe risk?

Tune thresholds and educate users; provide recovery via MDM.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-7(2)
  • Related controls: AC-7, AC-19, MP-6, SI-4

Need Help Implementing AC-7(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.