Bio fail then smart card
After biometric lock threshold, clinician must use smart card + PIN — not more fingerprint retries.
AC-7(4) enhances AC-7 by focusing on use of alternate authentication factor. After lock or failed biometrics, require an alternate authentication factor (password+MFA, smart card) rather than endless retries of the same weak factor. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Require an alternate authentication factor when unsuccessful logon thresholds are met, strengthening access to ePHI systems.
How this control shows up in healthcare and HIPAA-covered environments.
After biometric lock threshold, clinician must use smart card + PIN — not more fingerprint retries.
Locked password path requires MFA-backed alternate factor via approved recovery, not SMS to unknown numbers.
Admin accounts after failures must use phishing-resistant hardware key as alternate factor.
Assessors look for operating evidence of Use of Alternate Authentication Factor on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-7(4).
How this NIST control supports HIPAA Security Rule expectations.
A different authenticator type after failures — e.g., hardware key after bio lock.
No — alternate factor means a different authentication method.
Prefer phishing-resistant alternate factors.
Related controls that commonly accompany AC-7(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.