Control Objective
Stop ePHI from quietly moving onto systems you do not control — unless a documented, approved pathway with compensating safeguards exists.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Physician finishes notes on a home PC
A doctor downloads clinic documents to a personal desktop 'to finish later.' AC-20 policy forbids local download; instead she uses VDI or web EHR with clipboard/download restrictions so drafts never land on the home disk.
Billing contractor using their own laptop
An outsourced billing firm processes claims on company-owned, encrypted, MDM-enrolled laptops covered by a BAA — not employees' family computers. AC-20 is enforced contractually and technically via SSO conditions.
Staff upload to personal Dropbox for 'backup'
DLP flags an export of a patient list to a personal cloud account. Incident response revokes links, resets access, and retrains — reinforcing that personal cloud is an external system under AC-20.
Audit Considerations
Auditors ask where else ePHI lives. Be ready to show that personal and partner systems are either blocked or covered by BAAs plus technical restrictions. 'Everyone just uses their home computer' is a critical gap.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.308(b) Business Associate Contracts — external orgs creating/receiving ePHI need appropriate arrangements.
- 164.312(a)(1) Access Control — access from external systems must still be limited to authorized users under approved conditions.
- 164.310(d) Device and Media Controls — ePHI on devices/media you do not control creates custody gaps.
- 164.530(c) Safeguards (Privacy Rule) — reasonable administrative/technical/physical safeguards apply to how workforce handles PHI, including on external tools.