Nurse moves to quality analytics
Write access across all clinics is removed; read-only analytics roles are granted after approval — PS-5 prevents dual standing privileges.
PS-5 requires reviewing and confirming ongoing operational need for current logical and physical access authorizations to systems/facilities when individuals are reassigned or transferred, initiating related transfer actions within defined time periods, modifying access, and notifying defined personnel. Transfers are where privilege creep quietly accumulates ePHI rights.
Ensure movers lose access they no longer need and gain only what the new role requires — on a defined timeline with notifications to account and facility owners.
How this control shows up in healthcare and HIPAA-covered environments.
Write access across all clinics is removed; read-only analytics roles are granted after approval — PS-5 prevents dual standing privileges.
Old specialty work queues and shared drives are revoked within five business days per SLA.
Standard account remains for email; separate privileged account issued only after AT-3 training — transfer actions include authenticator changes.
Privilege creep after transfers shows up in access reviews. PS-5 evidence is timed tickets tied to HR events.
How this NIST control supports HIPAA Security Rule expectations.
PS-5 is event-driven at transfer time; AC-2 includes ongoing account management and periodic reviews. Use both.
Define an organization period (e.g., 5 business days) with faster SLAs for privileged roles.
Time-box dual access with end dates and monitoring — do not leave it permanent.
Related controls that commonly accompany PS-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.