Last success from odd city
Physician sees last successful logon from another state and last failures locally — triggers account review.
AC-9(2) enhances AC-9 by focusing on successful and unsuccessful logons. Notify users of both successful and unsuccessful logon history (time/location) so clinicians can spot account takeover of EHR identities. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Notify users of successful and unsuccessful logons to support detection of unauthorized use of healthcare accounts.
How this control shows up in healthcare and HIPAA-covered environments.
Physician sees last successful logon from another state and last failures locally — triggers account review.
Analyst notices a successful logon at 03:00 they did not make; incident ticket opened.
Portal shows both successful and unsuccessful recent logons with timestamps for user self-check.
Assessors look for operating evidence of Successful and Unsuccessful Logons on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(2).
How this NIST control supports HIPAA Security Rule expectations.
Yes — users need both to spot account takeover.
Show useful hints without oversharing sensitive network maps on public kiosks.
Provide clear 'report suspicious logon' contact.
Related controls that commonly accompany AC-9(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.