MA-2 Maintenance

Controlled Maintenance

Medium Risk Moderate Low Cost

MA-2 requires scheduling, documenting, and reviewing records of maintenance and repairs on system components; approving and monitoring non-local maintenance; and ensuring sanitization or personnel controls when equipment removed from the facility. Uncontrolled maintenance on EHR hosts and clinical devices is a frequent path for outages and unauthorized ePHI exposure.

Control Objective

Ensure maintenance on ePHI-related systems is approved, logged, supervised when needed, and does not bypass security or leave ePHI on removed media.

Implementation Guidance

  1. Require tickets for maintenance on in-scope systems with scope, window, and approver.
  2. Distinguish local vs remote/non-local maintenance; require stronger controls for remote (AC-17 vendor access).
  3. Supervise or session-monitor vendor remote maintenance when risk is high.
  4. Log what was done, who performed it, and verification after maintenance.
  5. If equipment leaves the site, apply MP-6 sanitization or continuous custody controls.
  6. Ban ad-hoc 'quick fixes' on production EHR without tickets except documented emergencies — then retro-log.
  7. Review maintenance logs periodically for anomalies.
  8. Include biomed and facility systems that connect to ePHI networks.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Overnight EHR vendor patch

Remote session is time-boxed, recorded, and approved under MA-2/AC-17; local IT watches; ticket closes with verification.

Disk replacement in a clinic server

Failed drive is destroyed under MP-6 rather than returned unsanitized; maintenance record links asset tag and certificate.

Unexpected after-hours remote login

Maintenance log review finds a vendor session without a ticket — access revoked and process reinforced.

Best Practices

  • Ticketed maintenance with approval.
  • Extra controls for remote vendor work.
  • Session monitoring for high-risk remote maintenance.
  • Sanitization when media leaves.
  • Emergency maintenance retro-documentation.
  • Periodic log review.

Common Gaps & Violations

  • Vendors with standing remote access and no tickets.
  • Hardware leaves with ePHI intact.
  • No records of what changed during maintenance.
  • Biomed work on networked devices invisible to IT.
  • Emergency fixes never documented.

Required Documentation

  • Controlled maintenance procedure
  • Maintenance ticket samples
  • Remote maintenance approval/monitoring rules
  • Equipment removal / sanitization linkage
  • Periodic maintenance log review evidence

How to Test & Validate

  1. Sample recent maintenance tickets for approval and closure notes.
  2. Verify a remote vendor session had authorization.
  3. Trace a removed drive to MP-6 evidence.
  4. Review emergency maintenance retro-logs.
  5. Confirm biomed networked maintenance is in scope.

Audit Considerations

Uncontrolled vendor maintenance is a favorite assessor question. Show tickets, remote access controls, and media handling.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a)(2)(iv) Maintenance Records — document repairs and modifications to physical components of facilities related to security.
  • 164.308(a)(1) Risk Management — maintenance without control is a risk to ePHI availability/confidentiality.
  • 164.312(a) Access Control — remote maintenance must not bypass access controls.
  • 164.310(d) Device and Media Controls — equipment removed for maintenance still requires ePHI protections.

Compliance Tips

  • One maintenance ticket type that forces security fields (remote Y/N, ePHI impact).
  • Pair MA-2 with AC-17 just-in-time vendor access.
  • Brief facilities/biomed teams — they often perform in-scope maintenance unknowingly.

Frequently Asked Questions

Does MA-2 apply to cloud EHR vendors?

You still control how and when vendor support accesses your tenant/environment; document approvals and monitoring expectations in the BAA/operating procedures.

How does MA-2 relate to CM-3?

CM-3 governs configuration change control broadly; MA-2 focuses on maintenance/repair activities and related remote/media controls.

What about emergency break-fix maintenance?

Allow it with clear criteria, then document promptly and review afterward.

References & Resources

  • NIST SP 800-53 Rev. 5 — MA-2
  • Related controls: MA-5, AC-17, MP-6, CM-3, CM-8

Need Help Implementing MA-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.