AC-19(4) Access Control

Restrictions for Sensitive Information

High Risk Moderate Medium Cost

AC-19(4) places additional restrictions on mobile devices when processing or storing sensitive organizational information. For healthcare, that means defining what ePHI may reside on phones/tablets at all — often favoring view-only virtual apps, blocking local downloads/exports, prohibiting clinical photography to personal camera rolls, and restricting offline chart caches on high-risk BYOD. Sensitivity-based rules go beyond baseline MDM enrollment.

Control Objective

Apply stricter mobile handling rules for ePHI and other sensitive healthcare data — minimizing local storage and high-risk capture/share paths.

Implementation Guidance

  1. Classify what sensitive information (ePHI, payment card, VIP) may be on mobile and under what ownership model.
  2. Prefer VDI/virtual app or secure browser with download/print disabled for high-sensitivity workflows.
  3. Block saving ePHI to personal cloud, SMS, or unmanaged camera rolls via DLP/MDM/app config.
  4. Require managed clinical camera apps for wound photography with audit trails.
  5. Limit offline EHR cache duration and encryption requirements.
  6. Prohibit local spreadsheets of patient lists on phones.
  7. Extra restrictions for executives/research devices handling sensitive populations.
  8. Review app store allowances for clinical roles (no consumer note apps for PHI).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

No download on BYOD EHR

Physicians view charts in a managed app that cannot export PDFs to personal storage — AC-19(4) sensitive-data restriction.

Wound photo policy

Bedside photography must use the EHR camera module, not the native camera; DLP flags PHI images in personal galleries.

Research coordinator tablet

Devices in a sensitive study get tighter offline limits and no local CSV exports of subject ePHI.

Best Practices

  • Minimize local ePHI on mobile.
  • Managed clinical camera workflows.
  • DLP for personal cloud/SMS.
  • Role-based mobile app allowlists.
  • Shorter offline caches for high sensitivity.
  • Train with concrete do/don’t examples.

Common Gaps & Violations

  • Unlimited EHR download to BYOD.
  • PHI wound photos in personal iCloud.
  • Patient lists in Notes/Keep apps.
  • Same mobile policy for public marketing tablets and oncology attendings.
  • No DLP on mail attachments to phones.

Required Documentation

  • Mobile sensitive information restrictions (AC-19(4))
  • Allowed mobile ePHI use cases matrix
  • App protection / DLP rule summaries
  • Clinical photography procedure
  • Exception register

How to Test & Validate

  1. Attempt download/export of ePHI from mobile EHR; confirm block where required.
  2. Verify managed camera path vs native camera controls.
  3. Test personal-cloud upload DLP with sample PHI string.
  4. Review offline cache settings for high-sensitivity roles.
  5. Sample devices for unauthorized note/cloud apps with PHI.

Audit Considerations

Privacy and security assessors ask where else ePHI lives on phones. Policy plus technical download blocks and photography controls evidence AC-19(4).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(4) Information Access Management — limit access/disclosure of ePHI including on mobile.
  • 164.530(c) Safeguards — reasonable safeguards against impermissible mobile disclosure.
  • 164.312(a)(1) Access Control — technical limits on what mobile sessions can store/export.
  • 164.310(d) Device and Media Controls — control ePHI on portable devices.

Compliance Tips

  • Publish a one-page ‘ePHI on mobile’ rulesheet for clinicians.
  • Start enforcement with block-download on BYOD mail/EHR.
  • Offer a corporate loaner for workflows that truly need offline files.

Frequently Asked Questions

Can any ePHI be on a phone?

Yes if risk-accepted and controlled (encrypted container, limited cache, no unrestricted export). AC-19(4) tightens rules for sensitive data — it does not always mean zero mobile ePHI.

Are SMS care-team texts allowed?

Generally avoid ePHI in consumer SMS; use managed secure messaging.

How does this differ from AC-19(1) encryption?

Encryption protects data at rest; AC-19(4) restricts whether and how sensitive data is allowed on the device at all.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-19(4)
  • Related controls: AC-19, AC-19(1), AC-20, SI-12, MP-5, SC-28

Need Help Implementing AC-19(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.