AC-9(3) Access Control

Notification of Account Changes

High Risk Moderate Medium Cost

AC-9(3) enhances AC-9 by focusing on notification of account changes. Notify users when account security attributes change (password reset, MFA device, email, privileged group) to catch helpdesk fraud or insider tampering. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Notify users of account changes that affect authentication or access to systems containing ePHI.

Implementation Guidance

  1. Notify on password, MFA, email, and privileged group changes.
  2. Prefer out-of-band notification channels.
  3. Include when/where change occurred at a safe detail level.
  4. Integrate with helpdesk fraud playbooks.
  5. Cover EHR-linked IdP as source of truth.
  6. Retain notification logs.
  7. Test that attacker in-session cannot suppress out-of-band notice.
  8. Extend to contractor accounts.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

MFA device added alert

User gets email/SMS that a new MFA method was registered — they did not request it; helpdesk investigates.

Password reset notification

Clinician notified of password change they did not initiate — stops helpdesk fraud early.

Privileged group change

Admin notified when added to EHR security-admin group unexpectedly.

Best Practices

  • Tie AC-9(3) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims notification of account changes but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Notification of Account Changes (AC-9(3))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to notification of account changes; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Notification of Account Changes on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(3).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(C) Log-in Monitoring — procedures for monitoring log-in attempts.
  • 164.312(b) Audit Controls — record and examine access activity.
  • 164.312(d) Person or Entity Authentication — detect misuse of credentials.
  • 164.308(a)(6) Security Incident Procedures — user notices can trigger early incident reporting.

Compliance Tips

  • List AC-9(3) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Which changes notify?

Password, MFA devices, email, and privileged group membership at minimum.

Out-of-band notice?

Prefer email/SMS out-of-band so an attacker in-session cannot hide the notice.

Helpdesk fraud?

Notifications are a primary control against social-engineering resets.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-9(3)
  • Related controls: AC-9, AC-2, IA-5

Need Help Implementing AC-9(3)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.