AC-19(5) Access Control

Full Device or Container-Based Encryption

High Risk Moderate Medium Cost

AC-19(5) requires employing organization-defined full-device encryption or container encryption to protect the confidentiality of information on organization-defined mobile devices. This is the explicit Rev. 5 enhancement many healthcare baselines select: choose the encryption style per device class (full-disk for corporate laptops/phones; container/app encryption for BYOD) and enforce it before ePHI access. It complements broader AC-19 policy with a concrete cryptographic mechanism requirement.

Control Objective

On defined mobile devices, enforce full-device or container-based encryption so confidentiality of ePHI is cryptographically protected if devices are lost, stolen, or decommissioned improperly.

Implementation Guidance

  1. Formally assign: corporate endpoints → full-device encryption; BYOD → container/app encryption (or both).
  2. Enforce via MDM compliance + conditional access gates to EHR/email/VPN.
  3. Escrow recovery keys; dual-control access to key vaults.
  4. Prohibit legacy devices that cannot meet encryption requirements from ePHI apps.
  5. Validate encryption after OS upgrades and device rebuilds.
  6. Extend to removable media used with mobile docks if in organizational definition.
  7. Report non-compliant unencrypted devices daily until remediated.
  8. Cross-reference AC-19(1) content in the SSP if both IDs appear in your catalog — same operational baseline.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Baseline selection in SSP

The organization selects AC-19(5) and defines ‘all corporate mobiles + BYOD with ePHI apps’ as in scope with BitLocker/FileVault or Intune app protection — auditors see a clear mechanism statement.

Non-compliant phone blocked

Encryption flag clears after OS wipe; conditional access blocks Outlook/EHR until encryption re-reports healthy.

Container for contractor BYOD

Billing contractors get encrypted work containers only — no full-device control of personal phones, meeting AC-19(5) via container encryption.

Best Practices

  • Write the org-defined assignment explicitly in the SSP.
  • Gate ePHI apps on compliance.
  • Monitor encryption KPIs.
  • Escrow keys with access logging.
  • Retire devices that cannot encrypt.
  • Test restore/recovery without weakening custody.

Common Gaps & Violations

  • AC-19(5) selected but encryption optional in MDM.
  • No definition of which devices/containers are in scope.
  • Recovery keys unmanaged.
  • Exceptions without risk acceptance.
  • Assuming cloud EHR means laptops need no disk encryption.

Required Documentation

  • AC-19(5) encryption mechanism assignment (full-device vs container by class)
  • MDM enforcement and conditional access evidence
  • Key escrow procedure
  • Compliance dashboards/KPIs
  • Risk acceptances for any gaps

How to Test & Validate

  1. Confirm SSP assignment language matches tooling.
  2. Block test: unencrypted device denied ePHI apps.
  3. Sample fleet encryption compliance ≥ policy threshold.
  4. Test recovery key retrieval with authorization.
  5. Verify BYOD container encryption policies active.

Audit Considerations

AC-19(5) is often a selected enhancement — expect to show the organization-defined encryption choice and technical enforcement for mobiles with ePHI.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(iv) Encryption and Decryption — implement encryption addressable specification via full-device/container mechanisms.
  • 164.310(d) Device and Media Controls — protect ePHI on portable devices.
  • 164.308(a)(1)(ii)(B) Risk Management — encryption is a primary treatment for mobile loss risk.
  • 164.312(a)(1) Access Control — confidentiality when devices leave the facility.

Compliance Tips

  • State in one sentence in the SSP: which devices use full-disk vs container encryption.
  • Do not leave AC-19(5) ‘planned’ while ePHI mail is already on phones.
  • Align laptop and phone programs so there is no unencrypted class of portable ePHI access.

Frequently Asked Questions

Full-device or container — which is required?

NIST lets the organization define which; pick per device class and enforce. Many healthcare orgs use both patterns.

Does AC-19(5) replace SC-28?

No. SC-28 is broader protection of information at rest; AC-19(5) specifically mandates full-device or container encryption on defined mobile devices.

Are ephemeral VDI thin clients in scope?

If they are organization-defined mobile/portable devices storing information, yes; pure stateless endpoints may be out of the assignment — document the decision.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-19(5)
  • NIST SP 800-124
  • Related controls: AC-19, AC-19(1), SC-28, MP-5, IA-2

Need Help Implementing AC-19(5)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.