AC-7(3) Access Control

Biometric Attempt Limiting

Medium Risk Moderate Medium Cost

AC-7(3) enhances AC-7 by focusing on biometric attempt limiting. Limit consecutive failed biometric attempts on shared clinical workstations and badge-bio doors to prevent spoofing/exhaustion attacks. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Limit the number of unsuccessful biometric logon attempts to protect biometric authenticators used for ePHI system access.

Implementation Guidance

  1. Identify biometric authenticators on clinical devices and doors.
  2. Set consecutive biometric failure limits.
  3. Fallback to alternate factors after limit.
  4. Alert on repeated failures suggesting spoofing.
  5. Protect biometric templates as sensitive.
  6. Tune for shared ED workstations.
  7. Document accessibility alternatives.
  8. Retest after device firmware updates.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Shared clinical workstation bio

Fingerprint reader on ED workstation limits failed biometric tries then falls back to password+MFA.

Badge-bio door to records room

Failed biometric attempts on HIM door lock out and alert security after threshold.

Spoofing attempt monitoring

Repeated bio failures on a VIP unit workstation generate SOC alert for possible spoofing.

Best Practices

  • Tie AC-7(3) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims biometric attempt limiting but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Biometric Attempt Limiting (AC-7(3))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to biometric attempt limiting; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Biometric Attempt Limiting on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(3).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — unique user identification and emergency access procedures supported by lockout hygiene.
  • 164.312(d) Person or Entity Authentication — protect authentication mechanisms from online guessing.
  • 164.308(a)(1) Risk Management — credential stuffing against clinical accounts is a known threat.
  • 164.312(a)(2)(iv) Encryption/Decryption (mobile) — wipe supports device ePHI protection when paired with AC-19.

Compliance Tips

  • List AC-7(3) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Why limit biometrics?

Limit spoofing/exhaustion and force fallback to stronger alternate factors.

Shared workstations?

Especially important on ED/nursing shared devices with bio readers.

Privacy of bio templates?

Protect biometric templates as sensitive authenticators (IA-5).

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-7(3)
  • Related controls: AC-7, IA-5, IA-5(1)

Need Help Implementing AC-7(3)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.