PS-7 Personnel Security

Third-Party Personnel Security

High Risk Moderate Low Cost

PS-7 requires establishing personnel security requirements — including roles and responsibilities — for third-party providers, notifying providers of those requirements, requiring providers to comply, and documenting personnel security requirements in contracts. Healthcare relies on coding vendors, IT contractors, cloud admins, and biomed techs; their people need security expectations comparable to employees when they can reach ePHI.

Control Objective

Ensure third-party personnel who access organizational systems or ePHI meet defined personnel security requirements enforced through contracts, onboarding, and offboarding.

Implementation Guidance

  1. Classify third parties by access level: physical only, logical to non-ePHI, logical to ePHI, privileged.
  2. Put personnel security clauses in BAAs/contracts: background checks where lawful, training, access agreements, breach notification duties, and return/destruction of credentials.
  3. Provision third-party accounts uniquely (no shared vendor logins) under AC-2/IA-2.
  4. Require named individuals on access requests; refresh rosters quarterly.
  5. Apply PS-4-equivalent offboarding when vendor staff rotate off the engagement.
  6. Verify training attestations for high-risk roles (AT-2/AT-3).
  7. Restrict third-party access with JIT/VPN and monitoring (AC-17/AU-2).
  8. Audit a sample of vendor personnel against contract requirements annually.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Overnight EHR support engineer from a BA

Named account, MFA, time-boxed VPN, and PS-6-equivalent acknowledgment are required before first login — contract language makes this enforceable.

Coding company staff turnover

Weekly roster update removes departed coders the same day; leftover accounts are found in a PS-7 audit and drive SLA penalties.

Biomed contractor replaces an MRI workstation OS

Personnel security requirements in the service agreement mandate escorted access and no USB exfil — verified on the maintenance ticket.

Best Practices

  • Tier requirements by access risk.
  • Contractual personnel clauses.
  • Named, unique accounts only.
  • Roster reconciliation.
  • Fast third-party offboarding.
  • Sample audits of vendor compliance.

Common Gaps & Violations

  • Shared 'vendor' accounts.
  • No personnel clauses in BAAs.
  • Unknown who at the BA still has VPN.
  • Background/training requirements never verified.
  • Contractors treated as out of scope for PS controls.

Required Documentation

  • Third-party personnel security standard
  • Contract/BAA clause library
  • Vendor personnel roster process
  • Onboarding/offboarding checklists for third parties
  • Sample attestation or audit results

How to Test & Validate

  1. Sample active third-party accounts against current vendor roster.
  2. Review a BAA for personnel security clauses.
  3. Verify offboarding of a recently rotated vendor employee.
  4. Confirm unique IDs (no shared logins).
  5. Check training/agreement evidence for privileged vendor users.

Audit Considerations

BA workforce access is a classic HIPAA weak spot. Assessors ask how you know which vendor humans still have access and under what personnel requirements.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — obtain satisfactory assurances; personnel controls support those assurances.
  • 164.314(a) Business Associate Contracts — require BA safeguards and workforce controls as appropriate.
  • 164.308(a)(3) Workforce Security — extend authorization/clearance concepts to third parties with access.
  • 164.308(a)(4) Information Access Management — manage third-party access to ePHI.

Compliance Tips

  • Maintain a 'humans with access' roster per BA, not only a company name on a VPN group.
  • Put roster refresh cadence in the SOW.
  • Kill shared vendor passwords as a priority remediation.

Frequently Asked Questions

Does PS-7 replace the BAA?

No. BAAs establish organizational obligations; PS-7 focuses on personnel security requirements for the individuals performing the work.

Are cloud providers' admins in scope?

You enforce via contract/BAA and shared-responsibility documentation; you may not screen hyperscaler staff personally, but you must understand and accept that model explicitly.

How does PS-7 relate to PS-4?

PS-4 is your termination process; for third parties, PS-7 requires providers to meet equivalent personnel exit/access-removal expectations.

References & Resources

  • NIST SP 800-53 Rev. 5 — PS-7
  • HIPAA §§ 164.308(b), 164.314
  • Related controls: PS-4, PS-6, SA-9, AC-17, AC-2

Need Help Implementing PS-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.