New ambulatory EHR go-live
AC-1 policy update clarifies clinic manager approval for ambulatory templates and forbids shared nursing logins before go-live training completes.
AC-1 requires developing, documenting, disseminating, reviewing, and updating an access control policy and procedures that address purpose, scope, roles, management commitment, coordination, and compliance — plus procedures to implement the Access Control family. In covered entities and BAs, AC-1 is the parent policy that binds EHR roles, break-glass, remote access, and vendor accounts to HIPAA minimum necessary and workforce clearance expectations.
Establish and maintain a living access control policy and supporting procedures that define how access to systems creating, receiving, maintaining, or transmitting ePHI is authorized, provisioned, reviewed, and revoked.
How this control shows up in healthcare and HIPAA-covered environments.
AC-1 policy update clarifies clinic manager approval for ambulatory templates and forbids shared nursing logins before go-live training completes.
Procedure under AC-1 requires BAA confirmation, data-use approval, and time-boxed service accounts — not ad-hoc VPN plus a shared SQL login.
Policy review resets who may authorize elevated EHR roles across the new enterprise directory before accounts are merged.
Assessors start family reviews at AC-1. A stale or generic policy while EHR privilege models are complex is a common finding that undermines downstream AC evidence.
How this NIST control supports HIPAA Security Rule expectations.
No. AC-1 must address the Access Control family — authorization, account management, least privilege, and related procedures for ePHI systems.
At least annually and whenever access models, EHR platforms, or organizational structure materially change.
Yes if they operate systems with ePHI; covered entities should also flow access expectations through BAAs and oversight.
Related controls that commonly accompany AC-1.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.