Personal Gmail prohibited
Policy/technical controls block ePHI to personal webmail; approved cloud EHR apps only.
AC-20(1) enhances AC-20 by focusing on limits on use. Limit how external systems may be used to process/store/transmit ePHI (approved cloud, prohibited personal Gmail, terms for affiliated clinics). Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Limit the use of external systems to process, store, or transmit ePHI according to organizational conditions.
How this control shows up in healthcare and HIPAA-covered environments.
Policy/technical controls block ePHI to personal webmail; approved cloud EHR apps only.
Independent clinic on hospital EHR must use only approved external access methods defined in limits-on-use.
CASB flags unsanctioned SaaS storing charts; use limited pending BAA and risk review.
Assessors look for operating evidence of Limits on Use on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-20(1).
How this NIST control supports HIPAA Security Rule expectations.
Limits on use of external systems include rules for personal cloud and email with ePHI.
Define allowed external access patterns in agreements and technical controls.
Not by name — but you need enforcement of the limits, not policy alone.
Related controls that commonly accompany AC-20(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.