Control Objective
Ensure identifiers uniquely and durably map to people, devices, and services — issued with authorization, not reused too soon, and disabled when inactive or no longer needed.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Rehired employee gets old ID immediately
A nurse returns after 18 months and is given the same EHR ID the day they left. Historical chart actions become ambiguous. IA-4 reuse rules keep the old ID retired and issue a new one (or enforce a long reuse ban) while preserving audit linkage in HR records.
Duplicate local EHR accounts
A clinic creates both jsmith and jane.smith in the EHR outside IAM. Access reviews miss one. IA-4 centralizes issuance so only IdP-mastered identifiers are provisioned downstream.
Device naming chaos on clinical workstations
Workstations named DESKTOP-XYZ cannot be tied to locations during an incident. IA-4 device identifier standards encode site/dept and asset tag for faster containment.
Audit Considerations
Assessors follow a log event to a real person. Broken identifier mapping or recycled clinical IDs undermine HIPAA unique user identification evidence.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.312(a)(2)(i) Unique User Identification — unique names and numbers for identifying and tracking user identity.
- 164.312(b) Audit Controls — useful audit records depend on stable identifiers.
- 164.308(a)(3) Workforce Security — identifier issuance aligns with workforce authorization.
- 164.312(d) Person or Entity Authentication — identifiers are the subject of authentication.