New coder cannot open EHR until agreement completes
IAM blocks role assignment until PS-6 acknowledgment is recorded — preventing 'access first, paperwork later'.
PS-6 requires developing and documenting access agreements for organizational systems, reviewing/updating them periodically, and ensuring individuals requiring access to organizational information and systems sign appropriate access agreements prior to being granted access. In healthcare, this includes confidentiality/user agreements covering ePHI, acceptable use, and sanctions awareness — distinct from but aligned with PL-4 rules of behavior.
Ensure every person granted access to ePHI systems has a current, appropriate access agreement on file before access is enabled and when agreements are updated.
How this control shows up in healthcare and HIPAA-covered environments.
IAM blocks role assignment until PS-6 acknowledgment is recorded — preventing 'access first, paperwork later'.
Elevated access requires an extra privileged-access agreement covering break-glass and audit monitoring expectations.
Updated access agreement adds generative-AI ePHI restrictions; LMS campaign forces re-ack before continued portal use.
Workforce security audits sample whether confidentiality/access agreements exist before ePHI access. Timing gaps are easy findings.
How this NIST control supports HIPAA Security Rule expectations.
PL-4 is the rules-of-behavior content and acknowledgment culture; PS-6 emphasizes documented access agreements as a precondition to granting system access.
The org BAA covers the entity; you may still require individual contractor acknowledgments when they receive accounts in your systems.
Yes if identity-bound, dated, and retained with the agreement version.
Related controls that commonly accompany PS-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.