AC-19(1) Access Control

Use of Full Device or Container-Based Encryption

High Risk Moderate Medium Cost

AC-19(1) focuses on employing cryptographic protection — commonly full-device encryption or container/app-level encryption — for mobile devices that handle organizational information. In healthcare, lost phones with secure chat, tablets with EHR apps, and laptops with offline charts must keep ePHI unreadable to finders. Prefer hardware-backed full-disk encryption for corporate devices and managed containers/app protection for BYOD so clinical content stays encrypted independently of personal photos.

Control Objective

Ensure mobile devices used with ePHI employ full-device and/or container-based encryption so lost or stolen devices do not yield readable protected health information.

Implementation Guidance

  1. Mandate FileVault/BitLocker (or platform equivalent) on corporate laptops accessing ePHI; verify recovery key escrow.
  2. Require device encryption before MDM marks phones/tablets compliant.
  3. For BYOD, deploy app containers / app protection policies that encrypt corporate email and EHR app data at rest.
  4. Block ePHI apps on unencrypted or non-compliant devices via conditional access.
  5. Cover loaner clinical tablets and shared ED devices — not only personally assigned phones.
  6. Test that selective wipe removes encrypted containers without needing the user passcode when policy allows.
  7. Document cryptography standards (algorithms, key custody).
  8. Align with AC-19(5) where baselines explicitly select full-device or container encryption as the organizational mechanism.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Stolen physician laptop

BitLocker-encrypted corporate laptop with offline notes yields no readable ePHI to the thief — AC-19(1) encryption in action.

BYOD secure messaging

Nurse’s personal phone uses an encrypted work container for clinical chat; personal camera roll stays separate and unencrypted work data is not stored in clear app sandboxes.

ED shared tablet

Supervised tablet with full-device encryption and managed EHR app meets encryption before it can open trauma-bay workflows.

Best Practices

  • Conditional access: no encryption, no ePHI apps.
  • Escrow recovery keys securely.
  • Prefer hardware-backed encryption.
  • Containerize BYOD.
  • Verify encryption state in MDM compliance reports.
  • Include loaners and shared devices.

Common Gaps & Violations

  • MDM installed but encryption not required.
  • Older Android/iOS devices without encryption still accessing email with ePHI.
  • Recovery keys only on the laptop sticker.
  • BYOD ActiveSync without app protection.
  • Shared tablets using personal Apple IDs without encryption enforcement.

Required Documentation

  • Mobile encryption standard (AC-19(1))
  • MDM compliance rules for encryption
  • Key escrow / recovery procedure
  • BYOD container architecture
  • Compliance report samples

How to Test & Validate

  1. Attempt ePHI app access on unencrypted test device; confirm block.
  2. Verify MDM reports encryption enabled on sample fleet.
  3. Confirm recovery key escrow for a corporate laptop.
  4. Validate container encryption / app protection on BYOD profile.
  5. Review exceptions for unencrypted devices.

Audit Considerations

HIPAA addressable encryption is frequently tested via mobile loss scenarios. Show enforced encryption compliance, not optional guidance.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(iv) Encryption and Decryption — addressable encryption of ePHI.
  • 164.310(d) Device and Media Controls — mobile devices are electronic media requiring safeguards.
  • 164.312(a)(1) Access Control — encryption supports confidentiality when devices leave controlled areas.
  • 164.308(a)(1) Risk Analysis — device loss/theft is a top healthcare risk.

Compliance Tips

  • Lead with email and EHR app enforcement — highest ePHI volume.
  • Track % encrypted compliant devices as a monthly KPI.
  • Pre-encrypt loaners before clinical distribution.

Frequently Asked Questions

Is container encryption enough without full-device encryption?

For BYOD it is often the practical control. Corporate-owned devices should generally use full-device encryption plus app controls.

How does AC-19(1) relate to AC-19(5)?

Both address full-device or container encryption on mobile devices; implement consistently and map both to your MDM encryption baseline where your catalog includes both IDs.

Do we need encryption if we wipe on loss?

Yes — wipe helps after report; encryption protects the window before wipe and cases never reported.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-19 / AC-19(5) family encryption enhancements
  • NIST SP 800-124 mobile security
  • Related controls: AC-19, AC-19(5), SC-28, MP-5, IA-2

Need Help Implementing AC-19(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.