Clinician sees failed logons
On next EHR login, RN is notified of three overnight unsuccessful attempts — reports possible attack.
AC-9(1) enhances AC-9 by focusing on unsuccessful logons. Notify users of unsuccessful logon attempts since last successful logon on EHR/VPN to help detect credential attacks against clinical accounts. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Notify the user of unsuccessful logon attempts to ePHI systems since the last successful logon.
How this control shows up in healthcare and HIPAA-covered environments.
On next EHR login, RN is notified of three overnight unsuccessful attempts — reports possible attack.
Remote coder sees unsuccessful VPN tries since last success and resets MFA device.
Message distinguishes unsuccessful attempts on the user's account, not the workstation's prior users.
Assessors look for operating evidence of Unsuccessful Logons on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(1).
How this NIST control supports HIPAA Security Rule expectations.
No — user notification complements centralized log-in monitoring.
Do not display details that help attackers (e.g., whether username exists) beyond the account owner session.
Ensure notice is for the authenticated user account.
Related controls that commonly accompany AC-9(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.