AC-9(2) Access Control

Successful and Unsuccessful Logons

Medium Risk Moderate Low Cost

AC-9(2) enhances AC-9 by focusing on successful and unsuccessful logons. Notify users of both successful and unsuccessful logon history (time/location) so clinicians can spot account takeover of EHR identities. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Notify users of successful and unsuccessful logons to support detection of unauthorized use of healthcare accounts.

Implementation Guidance

  1. Display both successful and unsuccessful recent logons.
  2. Include time and coarse location/channel hints.
  3. Prompt users to report unrecognized success.
  4. Tune detail level for clinical workflow speed.
  5. Cover remote access and EHR.
  6. Correlate user reports into IR process.
  7. Protect notice integrity from session attackers via out-of-band options where needed.
  8. Review effectiveness annually.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Last success from odd city

Physician sees last successful logon from another state and last failures locally — triggers account review.

Weekend success notice

Analyst notices a successful logon at 03:00 they did not make; incident ticket opened.

Combined history panel

Portal shows both successful and unsuccessful recent logons with timestamps for user self-check.

Best Practices

  • Tie AC-9(2) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims successful and unsuccessful logons but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Successful and Unsuccessful Logons (AC-9(2))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to successful and unsuccessful logons; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Successful and Unsuccessful Logons on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(C) Log-in Monitoring — procedures for monitoring log-in attempts.
  • 164.312(b) Audit Controls — record and examine access activity.
  • 164.312(d) Person or Entity Authentication — detect misuse of credentials.
  • 164.308(a)(6) Security Incident Procedures — user notices can trigger early incident reporting.

Compliance Tips

  • List AC-9(2) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Success and failure both?

Yes — users need both to spot account takeover.

Include geo/IP?

Show useful hints without oversharing sensitive network maps on public kiosks.

User reporting path?

Provide clear 'report suspicious logon' contact.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-9(2)
  • Related controls: AC-9, AC-9(1), AU-6

Need Help Implementing AC-9(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.