No download on BYOD EHR
Physicians view charts in a managed app that cannot export PDFs to personal storage — AC-19(4) sensitive-data restriction.
AC-19(4) places additional restrictions on mobile devices when processing or storing sensitive organizational information. For healthcare, that means defining what ePHI may reside on phones/tablets at all — often favoring view-only virtual apps, blocking local downloads/exports, prohibiting clinical photography to personal camera rolls, and restricting offline chart caches on high-risk BYOD. Sensitivity-based rules go beyond baseline MDM enrollment.
Apply stricter mobile handling rules for ePHI and other sensitive healthcare data — minimizing local storage and high-risk capture/share paths.
How this control shows up in healthcare and HIPAA-covered environments.
Physicians view charts in a managed app that cannot export PDFs to personal storage — AC-19(4) sensitive-data restriction.
Bedside photography must use the EHR camera module, not the native camera; DLP flags PHI images in personal galleries.
Devices in a sensitive study get tighter offline limits and no local CSV exports of subject ePHI.
Privacy and security assessors ask where else ePHI lives on phones. Policy plus technical download blocks and photography controls evidence AC-19(4).
How this NIST control supports HIPAA Security Rule expectations.
Yes if risk-accepted and controlled (encrypted container, limited cache, no unrestricted export). AC-19(4) tightens rules for sensitive data — it does not always mean zero mobile ePHI.
Generally avoid ePHI in consumer SMS; use managed secure messaging.
Encryption protects data at rest; AC-19(4) restricts whether and how sensitive data is allowed on the device at all.
Related controls that commonly accompany AC-19(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.