Storage array engineer on-site
OEM tech needs console access to a SAN hosting EHR VMs. MA-5 requires authorized ticket, escorted session, and time-boxed credentials — not a shared root password left with the vendor.
MA-5 requires establishing processes for authorizing maintenance personnel, ensuring personnel performing maintenance have required access authorizations, designating organizational personnel with required access who supervise maintenance activities of personnel without appropriate access, and escorting/monitoring when needed. Unescorted vendor techs on EHR hosts, PACS, or networked infusion pumps are a recurring healthcare risk.
Ensure only authorized, appropriately cleared people perform maintenance on ePHI-related systems — and that outsiders without full access rights are supervised so they cannot freely browse or copy patient data.
How this control shows up in healthcare and HIPAA-covered environments.
OEM tech needs console access to a SAN hosting EHR VMs. MA-5 requires authorized ticket, escorted session, and time-boxed credentials — not a shared root password left with the vendor.
Contractor updates drug-library firmware on networked pumps. Supervisor from clinical engineering stays present; wireless tools are approved; no free roaming on the clinical VLAN.
Facilities vendor enters a closet with network gear. Escort required; ports and consoles are not available without IT presence — physical maintenance still in MA-5 scope when systems can be touched.
Assessors ask who can put hands on production clinical systems. Uncontrolled OEM access is a frequent finding when BAAs exist but floor procedures do not.
How this NIST control supports HIPAA Security Rule expectations.
Yes if they can access systems or media that store/process ePHI — potential access still requires authorization and controls.
MA-2 controls the maintenance activity and records; MA-5 controls who is allowed to perform it and how they are supervised.
A BAA is necessary but not sufficient — you still need operational authorization, escort, and access hygiene.
Related controls that commonly accompany MA-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.