AC-20(2) Access Control

Portable Storage Devices — Non-Organizationally Owned Systems

High Risk Moderate Medium Cost

AC-20(2) enhances AC-20 by focusing on portable storage devices — non-organizationally owned systems. Restrict use of portable storage on non-owned systems and block ePHI copy to unmanaged USB/personal devices without encryption and approval. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Restrict portable storage device use involving non-organizationally owned systems that could expose ePHI.

Implementation Guidance

  1. Block unmanaged USB write of ePHI on clinical endpoints.
  2. Control portable storage on non-owned systems (vendor laptops).
  3. Provide approved encrypted media loaners.
  4. Disable storage on kiosks/public devices.
  5. Monitor USB events on ePHI workstations.
  6. Align with MP media controls.
  7. Train vendors at go-live.
  8. Exception process with expiry.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Clinic PC blocks personal USB

Unmanaged flash drives cannot copy charts from an EHR workstation.

Vendor laptop at go-live

Non-owned vendor laptops barred from writing ePHI to USB without loaner encrypted media.

Conference-room kiosk

Public-facing devices deny portable storage entirely to prevent casual PHI exfil.

Best Practices

  • Tie AC-20(2) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims portable storage devices — non-organizationally owned systems but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Portable Storage Devices — Non-Organizationally Owned Systems (AC-20(2))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to portable storage devices — non-organizationally owned systems; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Portable Storage Devices — Non-Organizationally Owned Systems on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-20(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — external systems/parties handling ePHI need appropriate agreements.
  • 164.312(a)(1) Access Control — limit where ePHI may be accessed or stored.
  • 164.310(d) Device and Media Controls — portable media controls for ePHI.
  • 164.308(a)(4) Information Access Management — govern access via external systems.

Compliance Tips

  • List AC-20(2) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Block all USB?

Risk-based — at least block unmanaged portable storage from writing ePHI on clinical endpoints.

Vendor laptops?

Treat as non-owned; prefer loaner managed devices for ePHI.

Encrypted USB OK?

Only if organizationally approved and controlled.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-20(2)
  • Related controls: AC-20, MP-2, MP-7, SC-7

Need Help Implementing AC-20(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.