MFA device added alert
User gets email/SMS that a new MFA method was registered — they did not request it; helpdesk investigates.
AC-9(3) enhances AC-9 by focusing on notification of account changes. Notify users when account security attributes change (password reset, MFA device, email, privileged group) to catch helpdesk fraud or insider tampering. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Notify users of account changes that affect authentication or access to systems containing ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
User gets email/SMS that a new MFA method was registered — they did not request it; helpdesk investigates.
Clinician notified of password change they did not initiate — stops helpdesk fraud early.
Admin notified when added to EHR security-admin group unexpectedly.
Assessors look for operating evidence of Notification of Account Changes on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(3).
How this NIST control supports HIPAA Security Rule expectations.
Password, MFA devices, email, and privileged group membership at minimum.
Prefer email/SMS out-of-band so an attacker in-session cannot hide the notice.
Notifications are a primary control against social-engineering resets.
Related controls that commonly accompany AC-9(3).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.