Automatic Logoff
Also known as: Automatic logout
A control that ends an idle session to prevent unauthorized access to PHI.
Automatic logoff is a technical safeguard that ends an electronic session after a period of inactivity, reducing the risk of unauthorized access to PHI on an unattended workstation or device. It is one of the technical safeguards named in the HIPAA Security Rule.
See how it fits alongside the other required controls in key security measures for HIPAA-compliant hosting. The full rule, and what timeout to set by workspace, is in HIPAA automatic logoff requirements. In a web app, the idle timeout is often a framework setting, and it may be off by default. Yii 2, for example, leaves its authTimeout setting unset. Our Yii HIPAA compliant guide shows how to set it and why cookie auto-login must stay off.