AC-8(2) Access Control

System Use Notification | Public Systems

Medium Risk Easy Low Cost

AC-8(2) enhances AC-8 by focusing on system use notification | public systems. Display appropriate use/monitoring notices on publicly accessible systems (patient kiosks, public health portals, career sites tied to org systems) where required. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Provide system use notifications on public-facing systems associated with the healthcare organization where information flow or access risks exist.

Implementation Guidance

  1. Inventory public systems (kiosks, public portals, public sites).
  2. Craft public-appropriate use/monitoring notices.
  3. Display notice before credential entry where applicable.
  4. Differentiate public vs workforce banner language.
  5. Review public notices when systems change.
  6. Ensure notices do not over-disclose security details.
  7. Include privacy links where appropriate.
  8. Test kiosk notice display after image updates.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Patient kiosk notice

Check-in kiosks display monitoring/acceptable-use notice before patients enter portal credentials.

Public health portal

Public symptom portal shows use/monitoring notice appropriate to a public system.

Career site SSO caution

Public careers site that deep-links into HR systems shows notice that activity may be monitored.

Best Practices

  • Tie AC-8(2) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims system use notification | public systems but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for System Use Notification | Public Systems (AC-8(2))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to system use notification | public systems; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of System Use Notification | Public Systems on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-8(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(A) Security Reminders — notices reinforce workforce security awareness.
  • 164.312(b) Audit Controls — banners often disclose monitoring of system activity.
  • 164.530(i) Policies and Procedures — communicate expectations for system use.
  • 164.308(a)(1) Risk Analysis — public systems introduce disclosure risk if notices/content unmanaged.

Compliance Tips

  • List AC-8(2) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Which systems are public?

Kiosks, public portals, and internet-facing systems not behind workforce auth.

Same banner as EHR?

Often shorter/public-appropriate language; still disclose monitoring if applicable.

Patient-facing required?

When the system is public and organization-controlled, provide appropriate notice.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-8(2)
  • Related controls: AC-8, AC-22

Need Help Implementing AC-8(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.