AC-9 Access Control

Previous Logon Notification

Medium Risk Easy Low Cost

AC-9 notifies the user, upon successful logon, of the date and time of the last successful logon and, where implemented, information about unsuccessful logon attempts since the last successful access. This simple feedback loop helps workforce members notice account misuse that automated tools may miss — especially shared workstations and remote access to ePHI systems.

Control Objective

Give authenticated users enough last-logon context to recognize possible unauthorized use of their credentials and report it quickly.

Implementation Guidance

  1. Enable last successful logon display after authentication on systems that support it (Windows, many EHRs, IdPs, VPN portals).
  2. Where possible, also show the count or timestamp of failed attempts since the prior successful logon.
  3. Train staff: if the last logon time/location looks wrong (e.g., login at 3 a.m. when they were off shift), report immediately to IT/security.
  4. For clinical shared-device workflows, pair AC-9 with unique user sessions (not shared passwords) or the notification becomes meaningless.
  5. Include previous-logon awareness in annual security training and phishing simulations follow-ups.
  6. If a legacy EHR cannot display last logon, compensate with email/IdP login alerts for new devices or anomalous locations.
  7. Document which systems implement AC-9 natively vs. compensating controls.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nurse notices overnight logon

A nurse logs into the EHR at 07:00 and sees last successful logon at 02:14. She was asleep. She reports it; investigation finds credential reuse from a personal email breach. Password reset and session termination (AC-12) stop further ePHI access.

Remote biller and travel anomaly

A remote coder's IdP shows last logon from an unfamiliar city. Combined with AC-7 lockout history, security confirms a stolen password attempt and enforces MFA enrollment the same day.

Admin console hygiene

Domain admins see previous privileged logon details on the bastion host, making it harder for a silent hijack to go unnoticed between change windows.

Best Practices

  • Display both last success and recent failures when the platform allows.
  • Teach staff what 'normal' looks like for their role.
  • Prefer per-user accounts so previous-logon data is attributable.
  • Supplement with modern login alerts (new device / new location) on cloud IdPs.
  • Log acknowledgment is optional; detection value comes from user attention plus reporting channels.

Common Gaps & Violations

  • Feature disabled on domain policy or EHR 'for performance.'
  • Shared logins make last-logon data useless noise.
  • No workforce training on how to react to suspicious last-logon data.
  • Relying only on AC-9 without MFA or monitoring for privileged accounts.

Required Documentation

  • Authentication standard describing previous-logon notification requirements
  • List of systems with native AC-9 vs compensating login alerts
  • Security awareness curriculum excerpt covering last-logon review
  • Incident reporting procedure for suspicious prior access

How to Test & Validate

  1. Log on to a test account twice and confirm the second session shows the first session's timestamp.
  2. Generate a failed logon, then succeed, and confirm failure information appears if required by your baseline.
  3. Interview a sample of users during walkthroughs: can they explain what to do if last logon looks wrong?
  4. Verify compensating alerts on systems without native banners.

Audit Considerations

AC-9 is often marked 'not selected' in some baselines, but when you claim it, show system evidence and user awareness. For HIPAA programs it is a low-cost detection control that supports login monitoring expectations.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(C) Log-in Monitoring — procedures for monitoring log-in attempts; AC-9 enlists the user as part of that monitoring loop.
  • 164.312(d) Person or Entity Authentication — supporting detection of credential misuse after authentication succeeds.
  • 164.308(a)(6) Incident Response — suspicious previous-logon reports should feed your IR process.

Compliance Tips

  • Add a one-slide reminder to new-hire IT onboarding: check last logon every morning.
  • For executives and admins with high-value accounts, enable push/email login notifications even if UI banners exist.

Frequently Asked Questions

Is AC-9 required in every NIST baseline?

Selection depends on your baseline/overlay. Even when optional, healthcare organizations often implement it because it is inexpensive and supports HIPAA login monitoring.

What if our EHR cannot show last logon?

Document the limitation and use IdP/SSO login notifications, email alerts, or SIEM user behavior alerts as compensating controls.

Does AC-9 replace SIEM monitoring?

No. It is a human-facing signal that complements centralized audit logging (AU family).

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-9 Previous Logon (Access) Notification
  • Related controls: AC-7, AC-11, AU-2, IA-2, IR-4

Need Help Implementing AC-9?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.