AC-9(4) Access Control

Additional Logon Information

Low Risk Easy Low Cost

AC-9(4) enhances AC-9 by focusing on additional logon information. Display additional logon information (last logon time, security reminders, policy links) without revealing sensitive security details to attackers. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Provide additional logon information to users of ePHI systems while avoiding disclosure that would aid adversaries.

Implementation Guidance

  1. Define additional logon information content (last logon, tips, links).
  2. Avoid revealing lockout thresholds or admin URLs to adversaries.
  3. Keep messaging concise for clinical users.
  4. Localize as needed.
  5. Update security tips seasonally (phishing campaigns).
  6. Ensure info displays post-auth where sensitive.
  7. Review content with privacy/comms.
  8. Verify on major apps annually.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Last logon time shown

EHR shows last logon time and contact for security without revealing full internal IP maps to attackers.

Security reminder link

Logon screen adds link to phishing reporting and acceptable use without sensitive config details.

Password expiry hint

Additional info shows days until password expiry for clinical accounts.

Best Practices

  • Tie AC-9(4) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims additional logon information but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Additional Logon Information (AC-9(4))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to additional logon information; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Additional Logon Information on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-9(4).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(C) Log-in Monitoring — procedures for monitoring log-in attempts.
  • 164.312(b) Audit Controls — record and examine access activity.
  • 164.312(d) Person or Entity Authentication — detect misuse of credentials.
  • 164.308(a)(6) Security Incident Procedures — user notices can trigger early incident reporting.

Compliance Tips

  • List AC-9(4) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

What extra info is OK?

Last logon time, security tips, policy links — not internal admin URLs or lockout thresholds that aid attackers.

Required by HIPAA?

Supports log-in monitoring awareness; define content via risk analysis.

Clutter clinical login?

Keep additional info concise for clinical workflows.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-9(4)
  • Related controls: AC-9, AC-8

Need Help Implementing AC-9(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.