AC-16 Access Control

Security and Privacy Attributes

High Risk Moderate Medium Cost

AC-16 requires organizations to provide and maintain security and privacy attributes for information in defined formats, associate attributes with subjects and objects as needed, and keep attribute values established and used consistently. In healthcare, sensitivity, care-team, location, consent, and purpose attributes enable EHR and data-platform decisions beyond coarse directory groups.

Control Objective

Define, assign, and maintain security/privacy attributes that healthcare systems use to authorize access, information flow, and handling of ePHI.

Implementation Guidance

  1. Inventory attribute vocabularies in EHR, IdP, DLP, and data lakes (role, sensitivity, purpose, consent, BA flag).
  2. Standardize formats and ownership for authoritative attribute sources.
  3. Bind attributes to accounts, roles, datasets, and interfaces at create/modify time.
  4. Enforce attributes in AC-3/AC-4 decisions where feasible.
  5. Protect attribute integrity—limit who can elevate sensitivity or clear consent flags.
  6. Log high-risk attribute changes.
  7. Align research vs treatment purpose attributes with Privacy Rule needs.
  8. Review attribute drift quarterly with HIM and security.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Care-team attributes gate chart access

EHR uses care-relationship and location attributes so float nurses see assigned unit charts—not the entire enterprise census.

Consent attribute blocks marketing use

A privacy attribute marks records research-only; CRM connectors refuse marketing exports when the attribute is set.

BA interface attribute

Messages to a billing BA carry an organization attribute that API gateways check before releasing full demographics.

Best Practices

  • Centralize attribute dictionaries.
  • Prefer system-enforced attributes over tribal knowledge.
  • Protect who can change sensitivity/consent attributes.
  • Log high-risk attribute changes.
  • Align with Privacy Rule purpose.
  • Reconcile IdP claims with EHR security attributes.

Common Gaps & Violations

  • Attributes documented but never enforced.
  • Spreadsheets as the only attribute store.
  • Consent flags cleared without audit.
  • Data lakes ignore source sensitivity labels.
  • Placeholder titles left with empty use cases.

Required Documentation

  • Attribute management standard (AC-16)
  • Attribute dictionary and owners
  • Enforcement points inventory
  • Change/audit samples for attribute edits
  • Privacy alignment notes

How to Test & Validate

  1. Trace a sample access decision to attributes used.
  2. Attempt unauthorized attribute elevation in test—expect deny/log.
  3. Verify downstream systems honor sensitivity labels.
  4. Review attribute change logs for 30 days.
  5. Confirm research extracts filter on purpose attributes.

Audit Considerations

Assessors ask how labels influence access—not whether a policy mentions attributes. Show live enforcement in EHR/IdP/DLP.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(4) Information Access Management — attributes support need-to-know decisions.
  • 164.312(a) Access Control — access established via attributes/roles.
  • 164.514 Minimum Necessary — purpose and sensitivity attributes operationalize minimum necessary.
  • 164.308(a)(1) Risk Analysis — mislabeled ePHI is a confidentiality risk.

Compliance Tips

  • Map AC-16 to ABAC/RBAC design in the SSP.
  • Start with consent and sensitivity attributes already in the EHR.
  • Include BA data feeds in attribute scope.

Frequently Asked Questions

Is AC-16 only for classified government systems?

No. Healthcare uses privacy and security attributes for ePHI handling, consent, and purpose.

Do AD groups count as attributes?

They can be one type; AC-16 also covers information object attributes and consistent maintenance.

How related to SC-16?

SC-16 addresses transmitting attributes; AC-16 addresses providing, associating, and maintaining them.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-16
  • Related controls: AC-3, AC-4, SC-16, SI-12, MP-3

Need Help Implementing AC-16?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.