Clarifications:
- There is no standard required for this criterion.
- To meet the requirements of this criterion, health IT must terminate a user’s access and subsequently require the user to re-authenticate using the same credentials used to originally gain access. [see also 77 FR 54250]
- This criterion is not meant to result in termination of network connections when user access is stopped after a period of inactivity, especially other network connections that are not in use by the health IT product. [see also 77 FR 54250]