AT-3 Awareness and Training

Role-Based Security Training

Medium Risk Moderate Low Cost

AT-3 requires providing role-based security training to personnel with assigned security roles and responsibilities before authorizing access to the system or performing assigned duties, when required by system changes, and at least annually thereafter. Unlike AT-2 awareness for everyone, AT-3 goes deeper for admins, developers, privacy investigators, and other specialized roles that can significantly affect ePHI.

Control Objective

Ensure people in elevated or specialized security-impacting roles receive targeted training matched to the risks they can create or control.

Implementation Guidance

  1. Identify roles needing AT-3: system admins, EHR security officers, developers, SOC analysts, privacy investigators, biomedical IT, and backup operators.
  2. Map curricula per role (e.g., admins: privileged access, logging; developers: secure coding, secrets; clinicians with break-glass: audit expectations).
  3. Deliver before elevated access is granted and refresh at least annually.
  4. Track completion in LMS tied to role assignment in IAM.
  5. Update content when platforms change (new IdP, new EHR modules).
  6. Include tabletop or lab exercises for IR and backup operators.
  7. Measure effectiveness (quizzes, phish for privileged users, config error rates).
  8. Retain records alongside AT-2 evidence.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

New EHR security admin

Before production rights, the admin completes AT-3 modules on role design, break-glass monitoring, and audit configuration — reducing misprovisioning.

Developers shipping a patient portal feature

Role-based secure SDLC training covers authZ bugs and logging of ePHI access before release.

Backup operators after ransomware tabletop

AT-3 refresh focuses on immutable backups, restore validation, and not using domain admin for backup consoles.

Best Practices

  • Curriculum mapped to job risks.
  • Gate privileged access on completion.
  • Annual refresh plus change-driven updates.
  • Hands-on labs for technical roles.
  • Separate from generic AT-2 awareness.
  • Track by role in LMS/IAM.

Common Gaps & Violations

  • Only AT-2 for everyone, including domain admins.
  • Training after access already granted indefinitely.
  • Generic content unrelated to EHR/admin duties.
  • No records by role.
  • Vendors with admin rights untrained on local procedures.

Required Documentation

  • Role-based training matrix (role → courses)
  • LMS completion reports by role
  • Course outlines/version history
  • Access-gating evidence for privileged roles
  • Update records after major system changes

How to Test & Validate

  1. Sample privileged users for AT-3 completion before access.
  2. Verify annual refresh rates for admin cohorts.
  3. Review curriculum relevance to current platforms.
  4. Confirm developers/admins are in the matrix.
  5. Check vendor/admin contractor coverage.

Audit Considerations

Assessors distinguish awareness from role-based training. Privileged users without specialized training are a common gap.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5) Security Awareness and Training — program includes role-appropriate training elements.
  • 164.308(a)(3) Workforce Security — workforce clearance and access paired with competence for duties.
  • 164.530(b) Training — Privacy Rule training complements security role training for PHI handlers.
  • 164.316 Documentation — retain training documentation.

Compliance Tips

  • Build an AT-3 track for 'EHR security admin' and 'IT privileged user' first.
  • Add training gates in the privileged access request workflow.
  • Refresh AT-3 after every major EHR or IdP upgrade.

Frequently Asked Questions

Who needs AT-3 vs AT-2?

Everyone with system access needs AT-2. People with security-impacting specialized duties need additional AT-3.

Are clinicians in scope for AT-3?

Some are — e.g., privacy investigators, health information managers, or users with break-glass authority — based on risk.

How often?

Before authorizing access/duties, when systems change, and at least annually.

References & Resources

  • NIST SP 800-53 Rev. 5 — AT-3
  • NIST SP 800-50
  • Related controls: AT-2, AC-6, IA-2, IR-2

Need Help Implementing AT-3?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.