HIE query for an ED patient
An ED physician queries a regional HIE. AC-21-aligned controls check purpose-of-use and patient consent flags before releasing encounter summaries — preventing a broad pull when the patient has restricted sharing.
AC-21 enables authorized users to determine whether access authorizations assigned to a sharing partner match the access restrictions on organizational information for collaborative information-sharing situations, and whether further information sharing is permitted. Practically, it is the control bridge between technical access rules and real-world sharing with HIEs, affiliated providers, public health, researchers, and BAs — so staff can tell what may be shared with whom.
Give people and systems a reliable way to decide if sharing ePHI with a partner is allowed under the applicable access restrictions — and to stop sharing when it is not.
How this control shows up in healthcare and HIPAA-covered environments.
An ED physician queries a regional HIE. AC-21-aligned controls check purpose-of-use and patient consent flags before releasing encounter summaries — preventing a broad pull when the patient has restricted sharing.
A coordinator asks IT for a clinic-wide identifiable export. Instead of a silent SQL dump, the sharing workflow checks IRB/authorization, applies minimum necessary fields, and records the decision — aligning AC-21 with privacy review.
A referral to an outside cardiology group uses a structured CCD via the approved network, not a full chart email. Sharing rules limit content to referral-relevant data and verify the recipient organization is on the approved partner list.
Assessors look for a usable decision process — not only a privacy policy PDF. Demonstrate partner lists, technical enforcement where available, and how restricted records are handled.
How this NIST control supports HIPAA Security Rule expectations.
Labels and attributes help, but AC-21 also covers processes that let users decide whether further sharing is allowed with a partner under existing restrictions.
AC-3 enforces access inside your systems; AC-4 constrains data paths; AC-21 focuses on collaborative sharing decisions with partners and matching their authorizations to your restrictions.
Yes — even occasional HIE, public health, or referral sharing needs a clear rule set so staff do not improvise with full-chart emails.
Related controls that commonly accompany AC-21.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.