New EHR security admin
Before production rights, the admin completes AT-3 modules on role design, break-glass monitoring, and audit configuration — reducing misprovisioning.
AT-3 requires providing role-based security training to personnel with assigned security roles and responsibilities before authorizing access to the system or performing assigned duties, when required by system changes, and at least annually thereafter. Unlike AT-2 awareness for everyone, AT-3 goes deeper for admins, developers, privacy investigators, and other specialized roles that can significantly affect ePHI.
Ensure people in elevated or specialized security-impacting roles receive targeted training matched to the risks they can create or control.
How this control shows up in healthcare and HIPAA-covered environments.
Before production rights, the admin completes AT-3 modules on role design, break-glass monitoring, and audit configuration — reducing misprovisioning.
Role-based secure SDLC training covers authZ bugs and logging of ePHI access before release.
AT-3 refresh focuses on immutable backups, restore validation, and not using domain admin for backup consoles.
Assessors distinguish awareness from role-based training. Privileged users without specialized training are a common gap.
How this NIST control supports HIPAA Security Rule expectations.
Everyone with system access needs AT-2. People with security-impacting specialized duties need additional AT-3.
Some are — e.g., privacy investigators, health information managers, or users with break-glass authority — based on risk.
Before authorizing access/duties, when systems change, and at least annually.
Related controls that commonly accompany AT-3.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.