Last logon time shown
EHR shows last logon time and contact for security without revealing full internal IP maps to attackers.
AC-9(4) enhances AC-9 by focusing on additional logon information. Display additional logon information (last logon time, security reminders, policy links) without revealing sensitive security details to attackers. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Provide additional logon information to users of ePHI systems while avoiding disclosure that would aid adversaries.
How this control shows up in healthcare and HIPAA-covered environments.
EHR shows last logon time and contact for security without revealing full internal IP maps to attackers.
Logon screen adds link to phishing reporting and acceptable use without sensitive config details.
Additional info shows days until password expiry for clinical accounts.
Assessors look for operating evidence of Additional Logon Information on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(4).
How this NIST control supports HIPAA Security Rule expectations.
Last logon time, security tips, policy links — not internal admin URLs or lockout thresholds that aid attackers.
Supports log-in monitoring awareness; define content via risk analysis.
Keep additional info concise for clinical workflows.
Related controls that commonly accompany AC-9(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.