PS-6 Personnel Security

Access Agreements

Medium Risk Easy Low Cost

PS-6 requires developing and documenting access agreements for organizational systems, reviewing/updating them periodically, and ensuring individuals requiring access to organizational information and systems sign appropriate access agreements prior to being granted access. In healthcare, this includes confidentiality/user agreements covering ePHI, acceptable use, and sanctions awareness — distinct from but aligned with PL-4 rules of behavior.

Control Objective

Ensure every person granted access to ePHI systems has a current, appropriate access agreement on file before access is enabled and when agreements are updated.

Implementation Guidance

  1. Define agreement types: workforce confidentiality/access agreement, privileged user agreement, remote access agreement, and contractor/BA individual acknowledgments where applicable.
  2. Gate account provisioning (AC-2) on completed agreement in HRIS/IAM.
  3. Include ePHI handling, minimum necessary, password/MFA duties, incident reporting, and sanctions references.
  4. Re-sign or re-acknowledge on material updates and at defined intervals (e.g., annual).
  5. Store agreements with timestamps and version IDs for audit retrieval.
  6. Cover students, volunteers, and temporary staff — not only employees.
  7. Align language with BAA obligations for individuals working under BA entities.
  8. Revoke access if agreement is refused or expired beyond grace policy.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

New coder cannot open EHR until agreement completes

IAM blocks role assignment until PS-6 acknowledgment is recorded — preventing 'access first, paperwork later'.

Privileged admin agreement for EHR DBAs

Elevated access requires an extra privileged-access agreement covering break-glass and audit monitoring expectations.

Annual policy refresh

Updated access agreement adds generative-AI ePHI restrictions; LMS campaign forces re-ack before continued portal use.

Best Practices

  • Provisioning gated on agreement.
  • Role-specific agreement variants.
  • Versioned storage with timestamps.
  • Periodic re-acknowledgment.
  • Include non-employees.
  • Tie refusal/expiry to access disable.

Common Gaps & Violations

  • Agreements collected after access is live.
  • Paper forms lost; no digital record.
  • Same generic form for privileged and standard users.
  • Contractors never sign.
  • No re-ack when policies change.

Required Documentation

  • Access agreement templates by role
  • Procedure linking agreements to provisioning
  • Acknowledgment/completion reports
  • Version history of agreement text
  • Exception / grace-period policy

How to Test & Validate

  1. Sample new accounts for agreement-before-access evidence.
  2. Verify privileged users have elevated agreements.
  3. Check contractor/student samples.
  4. Confirm re-ack after last material update.
  5. Attempt to find active users with missing/expired agreements.

Audit Considerations

Workforce security audits sample whether confidentiality/access agreements exist before ePHI access. Timing gaps are easy findings.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(3) Workforce Security — authorize and supervise workforce access appropriately.
  • 164.308(a)(4) Information Access Management — access policies supported by individual agreements.
  • 164.530(e) Sanctions — agreements put workforce on notice of consequences for violations.
  • 164.316 Policies and procedures — document agreements and retain acknowledgment evidence.

Compliance Tips

  • Make PS-6 a required checkbox in the joiner workflow before IdP activation.
  • Keep privileged agreements short and specific — DBAs actually read them.
  • Reconcile 'active EHR users' to 'current agreement on file' quarterly.

Frequently Asked Questions

How does PS-6 differ from PL-4?

PL-4 is the rules-of-behavior content and acknowledgment culture; PS-6 emphasizes documented access agreements as a precondition to granting system access.

Are BAAs enough for individuals at a vendor?

The org BAA covers the entity; you may still require individual contractor acknowledgments when they receive accounts in your systems.

Electronic signature OK?

Yes if identity-bound, dated, and retained with the agreement version.

References & Resources

  • NIST SP 800-53 Rev. 5 — PS-6
  • HIPAA §§ 164.308(a)(3)–(4), 164.530(e)
  • Related controls: PL-4, PS-7, AC-2, AT-2, AT-3

Need Help Implementing PS-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.