Denial of Access
Denial of access generally refers to preventing an authorized person or system from reaching resources they are permitted to use, or delaying time-sensitive operations. In a security context, this may result from a deliberate attack or from a technical failure or misconfiguration. The term can also be used more broadly in legal and administrative settings to describe being refused access to records, tribunals, or other protected rights.
In information security terms, denial of access is closely related to the concept of denial of service (DoS), which NIST defines as the prevention of authorized access to resources or the delaying of time-critical operations, where time-critical may range from milliseconds to hours. A denial-of-service attack is a cyberattack in which an adversary seeks to make a machine or network resource unavailable to its intended users. The specific application of denial of access within a given compliance program (for example, how it maps to Security Rule availability considerations or to particular controls) is context-dependent and is not defined by the evidence provided here; readers should verify the intended meaning against the relevant regulatory text or control framework. Note also that outside the security context, denial of access carries distinct meanings in legal and public-records settings, such as being refused inspection of public records or access to a tribunal, which are governed by separate authorities rather than by HIPAA.
Why it matters
Denial of access matters because the availability of information and systems is a core security objective, not merely a convenience. When an authorized person or system cannot reach the resources they are permitted to use, whether because of a deliberate attack or a technical failure, the consequences can range from operational disruption to, in time-sensitive settings, harm that unfolds in milliseconds or over hours. NIST characterizes denial of service as the prevention of authorized access to resources or the delaying of time-critical operations, underscoring that timing itself can be a critical dimension of the harm.
In a security context, denial of access is closely tied to denial-of-service (DoS) attacks, in which an adversary deliberately seeks to make a machine or network resource unavailable to its intended users. For organizations that handle sensitive information, an inability to access records or systems when needed can undermine both operations and the trust that authorized users and stakeholders place in those systems.
It is important to recognize that the term carries distinct meanings outside the security domain. In legal and public-records settings, denial of access can describe being refused inspection of public records or access to a tribunal, matters governed by separate authorities rather than by security frameworks. How denial of access maps to any particular compliance program's controls or availability considerations is context-dependent and should be verified against the relevant regulatory text or control framework.
Who it's relevant to
Inside Denial of Access
Common questions
Answers to the questions practitioners most commonly ask about Denial of Access.