Lost on-call phone with Secure Chat
A hospitalist's phone with a clinical messaging app is left in a rideshare. Because AC-19 required MDM and selective wipe, IT removes the work container within minutes; personal photos remain, ePHI does not.
AC-19 requires establishing usage restrictions and implementation guidance for organization-controlled mobile devices, and authorizing connection of mobile devices before they can access organizational systems. Phones, tablets, and laptops used for EHR apps, secure messaging, dictation, or VPN are high-loss, high-theft assets — AC-19 makes sure they meet encryption, authentication, and management bars before touching ePHI.
Prevent unmanaged or weakly protected mobile devices from becoming an easy exfiltration or loss path for ePHI, while still supporting clinicians who work on the move.
How this control shows up in healthcare and HIPAA-covered environments.
A hospitalist's phone with a clinical messaging app is left in a rideshare. Because AC-19 required MDM and selective wipe, IT removes the work container within minutes; personal photos remain, ePHI does not.
Physicians want EHR on personal iPads. Conditional access allows the EHR app only when the device is encrypted, PIN-locked, OS-current, and covered by app protection — blocking jailbroken or ancient iOS versions.
An emergency department shared tablet is enrolled as a supervised device with single-app or limited-app mode, auto-lock, and no consumer app store — reducing misconfiguration risk compared with unmanaged consumer tablets.
Auditors sample phones/tablets and ask how ePHI apps are controlled. 'We have MDM' without enforced compliance policies is insufficient. Show conditional access and wipe evidence.
How this NIST control supports HIPAA Security Rule expectations.
No. It requires usage restrictions and authorization. BYOD can work with app protection / MDM and clear ePHI handling rules.
Portable computing devices are in scope of the mobile device family of controls; apply laptop encryption, inventory, and remote wipe/lock consistently.
As soon as the loss is reported and identity is verified — measure in minutes when ePHI apps were installed. Document the SLA in your IR procedures.
Related controls that commonly accompany AC-19.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.