HIPA-13

Does your application automatically lock or log-out an account after a period of inactivity?

Explanation

This question is asking whether your application has an automatic timeout feature that either locks a user's session or logs them out completely after a period of inactivity. In the context of HIPAA (Health Insurance Portability and Accountability Act), this is a critical security control because it helps prevent unauthorized access to Protected Health Information (PHI) when a legitimate user leaves their workstation unattended with an active session. Without automatic timeouts, if a healthcare professional logs into your application and then walks away from their computer without logging out, anyone who has physical access to that computer could potentially view, modify, or steal sensitive patient information. The HIPAA Security Rule specifically addresses this in its technical safeguards under Access Control (45 CFR ยง 164.312(a)(2)(iii)), which requires implementation of 'automatic logoff' procedures to terminate electronic sessions after a predetermined time of inactivity. When answering this question, you should: 1. Clearly state whether your application has automatic timeout functionality 2. Specify the default timeout period (e.g., 15 minutes, 30 minutes) 3. Mention if the timeout period is configurable by administrators 4. Describe what happens when a timeout occurs (full logout vs. session lock requiring re-authentication) 5. Note any exceptions or special cases where timeouts might behave differently

Guidance

Refer to HIPAA regulations documentation for supplemental guidance in this section.

Example Responses

Example Response 1

Yes, our application implements automatic session timeout for security and HIPAA compliance After 15 minutes of user inactivity, the application automatically locks the user's session and requires re-authentication via password to resume This timeout period is configurable by system administrators through the security settings panel, allowing organizations to set stricter timeouts (as low as 5 minutes) or more lenient ones (up to 60 minutes) based on their security policies and operational needs All timeout events are logged in our audit system with timestamps and user identifiers to maintain a complete access record.

Example Response 2

Yes, our application enforces automatic logout after inactivity periods By default, the system will fully terminate a user's session after 30 minutes of inactivity, requiring a complete re-login with credentials For users accessing PHI, we enforce a stricter 10-minute timeout as an additional safeguard These timeout values are centrally managed by the organization's HIPAA Security Officer through our administrative console, and cannot be disabled Our system also provides visual warnings to users 2 minutes before timeout occurs, allowing them to extend their session if they're still working but haven't interacted with the application.

Example Response 3

No, our current application version does not automatically lock or log out accounts after inactivity periods While we recognize this is an important HIPAA requirement, our application was originally designed for non-healthcare sectors and we are currently in the process of implementing this feature Our development roadmap includes automatic session timeout functionality scheduled for release in our next major update (v4.2) in approximately 3 months In the interim, we recommend that our healthcare customers implement compensating controls such as workstation timeout policies at the operating system level and staff training on manual logout procedures when leaving workstations unattended.

Context

Tab
Case-Specific
Category
HIPAA Compliance

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron