AC-20 Access Control

Use of External Information Systems

High Risk Moderate Medium Cost

AC-20 restricts the use of external non-organizationally owned or managed information systems to process, store, or transmit organizational information, and limits the use of organizationally owned systems on external networks unless policy allows. In healthcare terms: personal home PCs, partner clinic machines, contractor laptops, and consumer cloud tools are external systems that need explicit rules before they touch ePHI.

Control Objective

Stop ePHI from quietly moving onto systems you do not control — unless a documented, approved pathway with compensating safeguards exists.

Implementation Guidance

  1. Define what 'external system' means for your org: personally owned PCs, contractor devices not in MDM, affiliated hospital networks, student devices, and consumer SaaS not under your BAA.
  2. Prohibit processing/storage of ePHI on external systems by default.
  3. Allow exceptions only through approved patterns: VDI/virtual apps (ePHI stays in the data center), browser access with download/print blocked, or managed BYOD under AC-19.
  4. Ban forwarding ePHI to personal email or uploading charts to personal Google Drive/Dropbox.
  5. Limit use of org-owned laptops on untrusted networks (hotel/public Wi-Fi) unless VPN and firewall policies are enforced.
  6. Require BAAs and security reviews before business processes move ePHI into external org systems.
  7. Train workforce with concrete 'do / do not' examples; monitor DLP alerts for personal-cloud uploads.
  8. Review exceptions quarterly and remove ones that became standing shadow IT.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Physician finishes notes on a home PC

A doctor downloads clinic documents to a personal desktop 'to finish later.' AC-20 policy forbids local download; instead she uses VDI or web EHR with clipboard/download restrictions so drafts never land on the home disk.

Billing contractor using their own laptop

An outsourced billing firm processes claims on company-owned, encrypted, MDM-enrolled laptops covered by a BAA — not employees' family computers. AC-20 is enforced contractually and technically via SSO conditions.

Staff upload to personal Dropbox for 'backup'

DLP flags an export of a patient list to a personal cloud account. Incident response revokes links, resets access, and retrains — reinforcing that personal cloud is an external system under AC-20.

Best Practices

  • Default deny ePHI on external systems; approve patterns, not one-off hope.
  • Prefer virtualization so data stays in your environment.
  • Combine AC-20 with DLP, CASB, and conditional access.
  • Put AC-20 language in contractor and student agreements.
  • Inventory sanctioned vs unsanctioned SaaS that may see ePHI.
  • Revisit rules when launching hybrid work or medical-student rotations.

Common Gaps & Violations

  • Policy silence on personal devices while everyone uses them for EHR.
  • ePHI in personal email threads and SMS.
  • Contractors accessing production on unmanaged PCs with stored passwords.
  • Org laptops used on open Wi-Fi without VPN.
  • Shadow IT forms (Typeform, personal Notion) collecting patient data without a BAA.

Required Documentation

  • Acceptable use / external systems policy (AC-20)
  • Approved access patterns (VDI, managed BYOD, sanctioned SaaS list)
  • BAA inventory for external orgs processing ePHI
  • Exception register with owners and expiry
  • DLP / conditional access rule evidence

How to Test & Validate

  1. From a personal unmanaged PC, attempt EHR login; confirm block or restricted VDI-only path.
  2. Verify download/print restrictions on the approved remote workspace.
  3. Sample contractor devices for enrollment and encryption.
  4. Review DLP incidents involving personal cloud or personal email.
  5. Confirm BAAs exist for external orgs in scope.

Audit Considerations

Auditors ask where else ePHI lives. Be ready to show that personal and partner systems are either blocked or covered by BAAs plus technical restrictions. 'Everyone just uses their home computer' is a critical gap.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — external orgs creating/receiving ePHI need appropriate arrangements.
  • 164.312(a)(1) Access Control — access from external systems must still be limited to authorized users under approved conditions.
  • 164.310(d) Device and Media Controls — ePHI on devices/media you do not control creates custody gaps.
  • 164.530(c) Safeguards (Privacy Rule) — reasonable administrative/technical/physical safeguards apply to how workforce handles PHI, including on external tools.

Compliance Tips

  • Publish a one-page 'Where ePHI is allowed' chart for staff.
  • Make VDI or virtual apps the easy path so people stop inventing risky shortcuts.
  • Add AC-20 checks to procurement when departments buy new SaaS.

Frequently Asked Questions

Can clinicians ever use a personal PC under AC-20?

Only if you authorize a controlled pattern — typically browser/VDI with downloads blocked and monitoring — not unrestricted local EHR clients storing charts on the home disk.

How is AC-20 different from AC-19?

AC-19 focuses on mobile device management controls. AC-20 is broader: any external/non-org system (including home desktops and partner networks) used with organizational information.

Does a BAA alone satisfy AC-20?

A BAA is necessary for many external orgs but not sufficient by itself — you still need usage restrictions and technical limits so ePHI does not spill into unapproved personal tools.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-20 Use of External Systems
  • HIPAA Security Rule §§ 164.308(b), 164.312(a), 164.310(d)
  • Related controls: AC-17, AC-19, CA-3, SA-9, SI-12

Need Help Implementing AC-20?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.