Shared clinical workstation bio
Fingerprint reader on ED workstation limits failed biometric tries then falls back to password+MFA.
AC-7(3) enhances AC-7 by focusing on biometric attempt limiting. Limit consecutive failed biometric attempts on shared clinical workstations and badge-bio doors to prevent spoofing/exhaustion attacks. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Limit the number of unsuccessful biometric logon attempts to protect biometric authenticators used for ePHI system access.
How this control shows up in healthcare and HIPAA-covered environments.
Fingerprint reader on ED workstation limits failed biometric tries then falls back to password+MFA.
Failed biometric attempts on HIM door lock out and alert security after threshold.
Repeated bio failures on a VIP unit workstation generate SOC alert for possible spoofing.
Assessors look for operating evidence of Biometric Attempt Limiting on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(3).
How this NIST control supports HIPAA Security Rule expectations.
Limit spoofing/exhaustion and force fallback to stronger alternate factors.
Especially important on ED/nursing shared devices with bio readers.
Protect biometric templates as sensitive authenticators (IA-5).
Related controls that commonly accompany AC-7(3).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.