Overnight EHR vendor patch
Remote session is time-boxed, recorded, and approved under MA-2/AC-17; local IT watches; ticket closes with verification.
MA-2 requires scheduling, documenting, and reviewing records of maintenance and repairs on system components; approving and monitoring non-local maintenance; and ensuring sanitization or personnel controls when equipment removed from the facility. Uncontrolled maintenance on EHR hosts and clinical devices is a frequent path for outages and unauthorized ePHI exposure.
Ensure maintenance on ePHI-related systems is approved, logged, supervised when needed, and does not bypass security or leave ePHI on removed media.
How this control shows up in healthcare and HIPAA-covered environments.
Remote session is time-boxed, recorded, and approved under MA-2/AC-17; local IT watches; ticket closes with verification.
Failed drive is destroyed under MP-6 rather than returned unsanitized; maintenance record links asset tag and certificate.
Maintenance log review finds a vendor session without a ticket — access revoked and process reinforced.
Uncontrolled vendor maintenance is a favorite assessor question. Show tickets, remote access controls, and media handling.
How this NIST control supports HIPAA Security Rule expectations.
You still control how and when vendor support accesses your tenant/environment; document approvals and monitoring expectations in the BAA/operating procedures.
CM-3 governs configuration change control broadly; MA-2 focuses on maintenance/repair activities and related remote/media controls.
Allow it with clear criteria, then document promptly and review afterward.
Related controls that commonly accompany MA-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.