AC-21 Access Control

Information Sharing

Medium Risk Moderate Medium Cost

AC-21 enables authorized users to determine whether access authorizations assigned to a sharing partner match the access restrictions on organizational information for collaborative information-sharing situations, and whether further information sharing is permitted. Practically, it is the control bridge between technical access rules and real-world sharing with HIEs, affiliated providers, public health, researchers, and BAs — so staff can tell what may be shared with whom.

Control Objective

Give people and systems a reliable way to decide if sharing ePHI with a partner is allowed under the applicable access restrictions — and to stop sharing when it is not.

Implementation Guidance

  1. Inventory recurring sharing relationships: HIE, affiliated hospitals, reference labs, public health reporting, research extracts, payer portals, and BA support access.
  2. For each partner, document the legal basis, permitted data types, purpose, and technical channel (HIE, sFTP, FHIR, portal).
  3. Tag or classify information (sensitivity, consent flags, special protections such as substance-use or psychotherapy notes where applicable).
  4. Provide users decision support: EHR break-the-glass rules, consent checks, sharing banners, or a disclosure desk for non-routine requests.
  5. Enforce partner-side access so recipients only receive what their authority allows (scopes, purpose-of-use, role filters).
  6. Log sharing decisions and disclosures for accounting where required.
  7. Train workforce on when to share vs escalate to privacy/compliance.
  8. Review partner entitlements when contracts, consent models, or state rules change.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

HIE query for an ED patient

An ED physician queries a regional HIE. AC-21-aligned controls check purpose-of-use and patient consent flags before releasing encounter summaries — preventing a broad pull when the patient has restricted sharing.

Research extract request

A coordinator asks IT for a clinic-wide identifiable export. Instead of a silent SQL dump, the sharing workflow checks IRB/authorization, applies minimum necessary fields, and records the decision — aligning AC-21 with privacy review.

Affiliated specialist referral

A referral to an outside cardiology group uses a structured CCD via the approved network, not a full chart email. Sharing rules limit content to referral-relevant data and verify the recipient organization is on the approved partner list.

Best Practices

  • Maintain a partner sharing register linked to BAAs/agreements.
  • Encode consent and special-protection flags where the EHR supports them.
  • Prefer structured, auditable channels over ad-hoc email attachments.
  • Give frontline staff a clear escalate path for edge cases.
  • Re-certify partner access scopes annually.
  • Align AC-21 procedures with HIPAA disclosure accounting and minimum necessary.

Common Gaps & Violations

  • Staff email full charts because it is faster than the approved channel.
  • HIE participation with no local guidance on consent or restricted records.
  • No partner inventory — teams invent one-off shares weekly.
  • Research pulls that ignore authorization basis.
  • BA support given unrestricted chart access without purpose limitation.

Required Documentation

  • Information sharing / disclosure procedure
  • Partner register (org, purpose, data types, channel, agreement)
  • Consent / restriction handling SOP
  • User guidance for EHR sharing features
  • Sample disclosure logs or accounting reports

How to Test & Validate

  1. Walk through an HIE or portal share with a restricted-consent test patient; confirm block or limited release.
  2. Attempt an ad-hoc email share of a test chart; confirm policy/DLP controls.
  3. Sample partner accounts for scope creep beyond the agreement.
  4. Verify disclosure logging for a non-routine share.
  5. Interview a clinical user: do they know when to escalate?

Audit Considerations

Assessors look for a usable decision process — not only a privacy policy PDF. Demonstrate partner lists, technical enforcement where available, and how restricted records are handled.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.502 / 164.506 Uses and Disclosures — sharing must match permitted purposes and authorizations.
  • 164.514(d) Minimum Necessary — limit shared PHI to what is needed for the purpose.
  • 164.528 Accounting of Disclosures — certain disclosures must be trackable.
  • 164.312(a)(1) Access Control — technical access for partners should reflect sharing authorities.

Compliance Tips

  • Put the partner register next to your BAA inventory — they should match.
  • Add sharing-decision tips to annual privacy training with real clinic scenarios.
  • When onboarding a new HIE, update AC-21 procedures before go-live — not after the first incident.

Frequently Asked Questions

Is AC-21 only about technical labels?

Labels and attributes help, but AC-21 also covers processes that let users decide whether further sharing is allowed with a partner under existing restrictions.

How does AC-21 relate to AC-3 and AC-4?

AC-3 enforces access inside your systems; AC-4 constrains data paths; AC-21 focuses on collaborative sharing decisions with partners and matching their authorizations to your restrictions.

Do small clinics need this if they rarely share?

Yes — even occasional HIE, public health, or referral sharing needs a clear rule set so staff do not improvise with full-chart emails.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-21 Information Sharing
  • HIPAA Privacy Rule §§ 164.502, 164.506, 164.514, 164.528
  • Related controls: AC-3, AC-4, AC-22, AU-2, CA-3

Need Help Implementing AC-21?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.