AC-20(1) Access Control

Limits on Use

High Risk Moderate Low Cost

AC-20(1) enhances AC-20 by focusing on limits on use. Limit how external systems may be used to process/store/transmit ePHI (approved cloud, prohibited personal Gmail, terms for affiliated clinics). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Limit the use of external systems to process, store, or transmit ePHI according to organizational conditions.

Implementation Guidance

  1. Define allowed external systems for ePHI processing/storage/transmission.
  2. Prohibit personal email/cloud for ePHI.
  3. Encode limits in CASB/proxy/email DLP.
  4. Set affiliate/external clinic use conditions.
  5. Require BAA before new external processing.
  6. Inventory shadow SaaS quarterly.
  7. Train workforce on limits.
  8. Escalate violations as incidents when ePHI involved.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Personal Gmail prohibited

Policy/technical controls block ePHI to personal webmail; approved cloud EHR apps only.

Affiliated clinic terms

Independent clinic on hospital EHR must use only approved external access methods defined in limits-on-use.

Shadow SaaS blocked

CASB flags unsanctioned SaaS storing charts; use limited pending BAA and risk review.

Best Practices

  • Tie AC-20(1) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims limits on use but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Limits on Use (AC-20(1))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to limits on use; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Limits on Use on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-20(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — external systems/parties handling ePHI need appropriate agreements.
  • 164.312(a)(1) Access Control — limit where ePHI may be accessed or stored.
  • 164.310(d) Device and Media Controls — portable media controls for ePHI.
  • 164.308(a)(4) Information Access Management — govern access via external systems.

Compliance Tips

  • List AC-20(1) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Personal devices?

Limits on use of external systems include rules for personal cloud and email with ePHI.

Affiliates?

Define allowed external access patterns in agreements and technical controls.

CASB required?

Not by name — but you need enforcement of the limits, not policy alone.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-20(1)
  • Related controls: AC-20, AC-17, CA-3

Need Help Implementing AC-20(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.