AC-2 Access Control Account Management

Account Management

High Risk Moderate Medium Cost

AC-2 requires the organization to manage information system accounts across their full lifecycle — defining account types, assigning account managers, establishing conditions for group and role membership, creating, enabling, modifying, disabling, and removing accounts, and monitoring account use. For covered entities and business associates, this is the operational backbone of unique user identification and workforce access to ePHI.

Control Objective

Ensure every account that can reach ePHI has a known owner, a documented business need, timely provisioning and deprovisioning, and periodic review so access does not outlive the job role.

Implementation Guidance

  1. Inventory account types: interactive user, privileged/admin, emergency/break-glass, service/API, vendor, temporary/student, and shared (minimize or eliminate shared).
  2. Name account managers (HR + IT + application owners) and define who approves access for each major system (EHR, billing, imaging, VPN, cloud IdP).
  3. Tie joiner/mover/leaver workflows to HR events: hire, transfer, leave of absence, termination — with same-day disable for involuntary exits when risk is high.
  4. Require documented approval before creating or escalating accounts; store tickets with role, systems, and justification.
  5. Run periodic access reviews (at least quarterly for ePHI systems; monthly for privileged accounts) and revoke unused or inappropriate access.
  6. Disable accounts after organization-defined inactivity; remove after a retention window if no longer needed.
  7. Monitor for orphaned accounts, dormant privileged IDs, and accounts created outside the official process.
  8. Extend the same lifecycle rules to BA/vendor accounts and temporary clinical students — not only employees.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Same-day termination of a billing clerk

A revenue-cycle clerk is terminated at 10:00. Without AC-2 discipline, EHR and clearinghouse logins stay active for days. A documented leaver checklist disables IdP, EHR, VPN, and email within hours, and an access review later confirms no residual roles remained.

Role change from nurse to quality analyst

A nurse moves to quality improvement and no longer needs broad charting write access across all clinics. AC-2 mover workflow removes floor EHR roles and grants read-focused analytics access with manager approval — preventing privilege accumulation.

Vendor support account left open

A PACS vendor was given a temporary admin account for a go-live weekend. Six months later it still works. AC-2 temporary-account rules with expiry dates and monthly privileged review catch and remove it before an audit finding — or a breach.

Best Practices

  • Prefer role-based access (RBAC) packages over one-off permissions.
  • Separate standard and privileged accounts for the same person.
  • Automate disablement from HRIS where possible; keep a manual break-glass path for emergencies.
  • Track emergency accounts with heightened logging and post-use review.
  • Include non-employees (contractors, students, vendors) in the same inventory.
  • Measure time-to-revoke after termination as a compliance KPI.

Common Gaps & Violations

  • Accounts created by application admins with no ticket or approval trail.
  • Terminated workforce still appearing in EHR active-user reports.
  • Privilege creep after multiple role changes with no access cleanup.
  • Shared department logins that break accountability.
  • Service accounts with interactive logon and no owner.
  • Access reviews done on paper once a year with no evidence of remediations.

Required Documentation

  • Account management / access control procedures
  • Joiner-mover-leaver (JML) workflow and RACI
  • Role catalogs for major ePHI systems
  • Access request / approval records
  • Periodic access review reports and remediation tickets
  • Privileged and emergency account inventory

How to Test & Validate

  1. Sample recent hires: confirm accounts were created only after approval and matched the assigned role.
  2. Sample recent terminations: confirm disable/remove timestamps align with policy SLAs.
  3. Pull dormant-account reports (e.g., 30/60/90 days) and verify follow-up.
  4. Recalculate a privileged access review: were exceptions closed?
  5. Attempt to identify shared or generic accounts in EHR/IdP exports.

Audit Considerations

Auditors compare HR termination lists to active-directory/EHR user lists, sample access tickets, and ask how movers are handled. Gaps between HR and IT are the most common AC-2 finding in healthcare assessments.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — unique user identification and procedures allowing access only to authorized persons or software programs.
  • 164.308(a)(3)(ii)(A) Authorization and/or Supervision — workforce access authorization aligns with account provisioning.
  • 164.308(a)(3)(ii)(C) Termination Procedures — ending access when employment ends maps directly to AC-2 disable/remove.
  • 164.308(a)(4) Information Access Management — isolating and clearing access based on role supports account lifecycle discipline.

Compliance Tips

  • Put numeric SLAs in policy (e.g., disable within 24 hours of termination notice).
  • Feed IdP as the source of truth; push deprovisioning downstream to EHR and SaaS.
  • Add account-management checks to BA onboarding questionnaires.

Frequently Asked Questions

How often should we review accounts for AC-2?

Review privileged accounts at least monthly and standard ePHI users at least quarterly, plus event-driven reviews after major org changes.

Are service accounts in scope?

Yes. They need an owner, purpose, minimal privileges, and a review cycle — often stricter than human accounts.

Does AC-2 replace access enforcement (AC-3)?

No. AC-2 decides who should have an account and which roles; AC-3 enforces those decisions technically at runtime.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-2 Account Management
  • NIST SP 800-162 (ABAC concepts) and RBAC guidance
  • HIPAA Security Rule §§ 164.308(a)(3)–(4), 164.312(a)
  • Related controls: AC-3, AC-5, AC-6, IA-2, IA-4, PS-4

Need Help Implementing AC-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.