MA-5 Maintenance

Maintenance Personnel

High Risk Moderate Low Cost

MA-5 requires establishing processes for authorizing maintenance personnel, ensuring personnel performing maintenance have required access authorizations, designating organizational personnel with required access who supervise maintenance activities of personnel without appropriate access, and escorting/monitoring when needed. Unescorted vendor techs on EHR hosts, PACS, or networked infusion pumps are a recurring healthcare risk.

Control Objective

Ensure only authorized, appropriately cleared people perform maintenance on ePHI-related systems — and that outsiders without full access rights are supervised so they cannot freely browse or copy patient data.

Implementation Guidance

  1. Maintain an authorized maintainer list (employees, biomed, contracted OEMs) tied to systems and facilities.
  2. Require badging, identity check, and ticketed scope before work begins (pairs with MA-2).
  3. For vendors lacking full system authorization, assign an escort/supervisor who does have authorization.
  4. Prefer just-in-time accounts over standing vendor admin; disable after the window.
  5. Prohibit unsupervised use of portable media on ePHI systems unless approved and scanned.
  6. Document citizenship/clearance-style requirements only where your risk model or contracts demand them; otherwise document equivalent trust criteria (BAA, screening).
  7. Brief maintainers on minimum necessary and no photography of screens with ePHI.
  8. Review maintainer access quarterly; remove departed vendor techs promptly (PS-4 analog for vendors).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Storage array engineer on-site

OEM tech needs console access to a SAN hosting EHR VMs. MA-5 requires authorized ticket, escorted session, and time-boxed credentials — not a shared root password left with the vendor.

Biomed pump patching

Contractor updates drug-library firmware on networked pumps. Supervisor from clinical engineering stays present; wireless tools are approved; no free roaming on the clinical VLAN.

After-hours HVAC vendor in the data closet

Facilities vendor enters a closet with network gear. Escort required; ports and consoles are not available without IT presence — physical maintenance still in MA-5 scope when systems can be touched.

Best Practices

  • Authorized maintainer roster per critical system.
  • Escort rule for personnel without appropriate access.
  • JIT vendor accounts with session logging.
  • No shared maintainer passwords.
  • Quarterly roster cleanup.
  • Cover biomed and facilities, not only IT OEMs.

Common Gaps & Violations

  • Standing vendor VPN with no named technicians.
  • Unescorted access to EHR server rooms.
  • Shared break-glass passwords given to any visiting tech.
  • Biomed work invisible to security.
  • Departed vendor staff still on badge lists.

Required Documentation

  • Maintenance personnel authorization procedure
  • Authorized maintainer / vendor tech roster
  • Escort and supervision rules
  • Sample escorted maintenance tickets
  • Vendor account issuance/disable evidence

How to Test & Validate

  1. Sample recent vendor maintenance for authorization and escort evidence.
  2. Confirm JIT or named accounts — not shared generics.
  3. Review roster against active badges/VPN users.
  4. Observe or interview biomed process for networked devices.
  5. Verify post-maintenance credential disable.

Audit Considerations

Assessors ask who can put hands on production clinical systems. Uncontrolled OEM access is a frequent finding when BAAs exist but floor procedures do not.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — people performing work on systems need appropriate authorization and supervision.
  • 164.308(b) Business Associate Contracts — maintenance vendors who may access ePHI require BAAs and operational controls.
  • 164.310(a) Facility Access Controls — limit physical access during maintenance in sensitive areas.
  • 164.312(a) Access Control — technical access for maintainers must be authorized and unique where feasible.

Compliance Tips

  • Put escort required Y/N on every maintenance ticket template.
  • Pair MA-5 with AC-17 for remote OEM sessions.
  • Train facilities staff — they often admit vendors without IT notice.

Frequently Asked Questions

Does MA-5 apply if the vendor never sees ePHI on screen?

Yes if they can access systems or media that store/process ePHI — potential access still requires authorization and controls.

How does MA-5 differ from MA-2?

MA-2 controls the maintenance activity and records; MA-5 controls who is allowed to perform it and how they are supervised.

Can we rely only on the BAA?

A BAA is necessary but not sufficient — you still need operational authorization, escort, and access hygiene.

References & Resources

  • NIST SP 800-53 Rev. 5 — MA-5
  • Related controls: MA-2, MA-4, AC-17, PS-3, PE-2, PE-3

Need Help Implementing MA-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.