Baseline selection in SSP
The organization selects AC-19(5) and defines ‘all corporate mobiles + BYOD with ePHI apps’ as in scope with BitLocker/FileVault or Intune app protection — auditors see a clear mechanism statement.
AC-19(5) requires employing organization-defined full-device encryption or container encryption to protect the confidentiality of information on organization-defined mobile devices. This is the explicit Rev. 5 enhancement many healthcare baselines select: choose the encryption style per device class (full-disk for corporate laptops/phones; container/app encryption for BYOD) and enforce it before ePHI access. It complements broader AC-19 policy with a concrete cryptographic mechanism requirement.
On defined mobile devices, enforce full-device or container-based encryption so confidentiality of ePHI is cryptographically protected if devices are lost, stolen, or decommissioned improperly.
How this control shows up in healthcare and HIPAA-covered environments.
The organization selects AC-19(5) and defines ‘all corporate mobiles + BYOD with ePHI apps’ as in scope with BitLocker/FileVault or Intune app protection — auditors see a clear mechanism statement.
Encryption flag clears after OS wipe; conditional access blocks Outlook/EHR until encryption re-reports healthy.
Billing contractors get encrypted work containers only — no full-device control of personal phones, meeting AC-19(5) via container encryption.
AC-19(5) is often a selected enhancement — expect to show the organization-defined encryption choice and technical enforcement for mobiles with ePHI.
How this NIST control supports HIPAA Security Rule expectations.
NIST lets the organization define which; pick per device class and enforce. Many healthcare orgs use both patterns.
No. SC-28 is broader protection of information at rest; AC-19(5) specifically mandates full-device or container encryption on defined mobile devices.
If they are organization-defined mobile/portable devices storing information, yes; pure stateless endpoints may be out of the assignment — document the decision.
Related controls that commonly accompany AC-19(5).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.