PS-5 Personnel Security

Personnel Transfer

Medium Risk Moderate Low Cost

PS-5 requires reviewing and confirming ongoing operational need for current logical and physical access authorizations to systems/facilities when individuals are reassigned or transferred, initiating related transfer actions within defined time periods, modifying access, and notifying defined personnel. Transfers are where privilege creep quietly accumulates ePHI rights.

Control Objective

Ensure movers lose access they no longer need and gain only what the new role requires — on a defined timeline with notifications to account and facility owners.

Implementation Guidance

  1. Trigger PS-5 from HR job-change events (department, title, location, supervisor).
  2. Within defined days, review logical roles (EHR, file shares, VPN, admin) and physical access areas.
  3. Remove old entitlements before or as new ones are granted — avoid stacking.
  4. Notify system and facility owners of the transfer.
  5. Reissue or adjust authenticators if role assurance changes.
  6. Include transfers to/from privileged IT and privacy roles as high priority.
  7. Spot-check transfers in quarterly access reviews (AC-2).
  8. Cover affiliated/contractor role changes, not only employees.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Nurse moves to quality analytics

Write access across all clinics is removed; read-only analytics roles are granted after approval — PS-5 prevents dual standing privileges.

Billing staff transfers to another specialty

Old specialty work queues and shared drives are revoked within five business days per SLA.

IT helpdesk promoted to server admin

Standard account remains for email; separate privileged account issued only after AT-3 training — transfer actions include authenticator changes.

Best Practices

  • HR-triggered mover workflows.
  • Remove-then-add entitlement pattern.
  • SLAs for transfer access updates.
  • Notify owners automatically.
  • Higher scrutiny for privileged role changes.
  • Validate in periodic access reviews.

Common Gaps & Violations

  • New role access added; old access never removed.
  • Transfers ignored until annual review.
  • Physical access not updated with logical access.
  • No notifications to app owners.
  • Contractor role changes invisible to IT.

Required Documentation

  • Personnel transfer procedure
  • Mover checklist / workflow screenshots
  • SLA definitions
  • Sample completed transfer tickets
  • Notification templates to owners

How to Test & Validate

  1. Sample recent transfers for timely entitlement changes.
  2. Confirm old EHR roles removed.
  3. Verify physical access updates when location changes.
  4. Check privileged transfers for training gates.
  5. Review SLA breaches and backlog.

Audit Considerations

Privilege creep after transfers shows up in access reviews. PS-5 evidence is timed tickets tied to HR events.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — access authorization should match current duties.
  • 164.308(a)(4) Information Access Management — establish, document, review, and modify access.
  • 164.312(a)(1) Access Control — technical access must reflect current authorizations.
  • 164.308(a)(3)(ii)(B) Workforce Clearance — clearance/access appropriateness as roles change.

Compliance Tips

  • Integrate HRIS transfer events into IAM tickets automatically.
  • Report 'mound of leftover roles' as a metric after transfers.
  • Treat clinic-to-clinic moves as transfers even if title is unchanged.

Frequently Asked Questions

How is PS-5 different from AC-2 access reviews?

PS-5 is event-driven at transfer time; AC-2 includes ongoing account management and periodic reviews. Use both.

How fast must transfer access change?

Define an organization period (e.g., 5 business days) with faster SLAs for privileged roles.

What if someone covers two roles temporarily?

Time-box dual access with end dates and monitoring — do not leave it permanent.

References & Resources

  • NIST SP 800-53 Rev. 5 — PS-5
  • HIPAA §§ 164.308(a)(3)–(4)
  • Related controls: AC-2, AC-6, PS-4, PE-2, AT-3

Need Help Implementing PS-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.