Control Objective
Ensure every person who accesses systems with ePHI sees a clear, approved notice about authorized use, monitoring, and privacy expectations before interactive access begins.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
VPN banner for remote clinical staff
Telehealth nurses VPN into the clinic network. The VPN portal shows an AC-8 banner stating the connection is monitored and limited to assigned clinical duties. When a later investigation reviews anomalous file access, the organization can show users were notified that activity could be logged.
EHR workstation at check-in desk
Front-desk PCs display a Windows interactive logon banner before the EHR SSO prompt. Temporary staff and students see the same notice as full-time employees, reducing 'I didn't know monitoring applied to me' disputes.
Cloud EMR admin console
Super-user access to a cloud EMR configuration portal requires acknowledging a stricter banner that references privileged access responsibilities and sanctions screening expectations.
Audit Considerations
Assessors sample logon paths and compare displayed text to the approved notice. Gaps on remote access or privileged consoles are common findings. Keep proof of legal review for the language.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.308(a)(5)(i) Security Awareness Training — workforce should understand acceptable use; AC-8 reinforces that at logon.
- 164.312(b) Audit Controls — monitoring notices support the legitimacy of reviewing system activity logs containing ePHI access.
- 164.530(e) Sanctions — clear notice strengthens enforcement when workforce members misuse systems.
Privacy Rule transparency expectations for patients are separate; AC-8 primarily addresses workforce/system users.