Control Objective
Ensure every account that can reach ePHI has a known owner, a documented business need, timely provisioning and deprovisioning, and periodic review so access does not outlive the job role.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Same-day termination of a billing clerk
A revenue-cycle clerk is terminated at 10:00. Without AC-2 discipline, EHR and clearinghouse logins stay active for days. A documented leaver checklist disables IdP, EHR, VPN, and email within hours, and an access review later confirms no residual roles remained.
Role change from nurse to quality analyst
A nurse moves to quality improvement and no longer needs broad charting write access across all clinics. AC-2 mover workflow removes floor EHR roles and grants read-focused analytics access with manager approval — preventing privilege accumulation.
Vendor support account left open
A PACS vendor was given a temporary admin account for a go-live weekend. Six months later it still works. AC-2 temporary-account rules with expiry dates and monthly privileged review catch and remove it before an audit finding — or a breach.
Audit Considerations
Auditors compare HR termination lists to active-directory/EHR user lists, sample access tickets, and ask how movers are handled. Gaps between HR and IT are the most common AC-2 finding in healthcare assessments.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.312(a)(1) Access Control — unique user identification and procedures allowing access only to authorized persons or software programs.
- 164.308(a)(3)(ii)(A) Authorization and/or Supervision — workforce access authorization aligns with account provisioning.
- 164.308(a)(3)(ii)(C) Termination Procedures — ending access when employment ends maps directly to AC-2 disable/remove.
- 164.308(a)(4) Information Access Management — isolating and clearing access based on role supports account lifecycle discipline.