AC-21(1) Access Control

Automated Decision Support

Medium Risk Complex Medium Cost

AC-21(1) enhances AC-21 by focusing on automated decision support. Provide automated decision support for information-sharing choices (whether a disclosure is permitted) to reduce erroneous ePHI releases. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Employ automated decision support to help users decide whether sharing or accessing information is appropriate under policy.

Implementation Guidance

  1. Identify sharing decisions that benefit from automation (ROI, EHR share).
  2. Encode policy rules for common disclosure types.
  3. Present guidance in-workflow before release.
  4. Escalate ambiguous cases to privacy/HIM.
  5. Log recommendations and user actions.
  6. Update rules when regulations/policies change.
  7. Measure reduced erroneous releases.
  8. Avoid over-automation that hides accountability.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

ROI decision helper

HIM clerk enters disclosure type; tool recommends whether authorization is needed before release.

Provider share prompt

Physician sharing CCD externally gets automated guidance on minimum necessary and prohibited elements.

Research vs TPO classifier

Automated support flags when a request looks like research rather than treatment — routes to IRB/privacy.

Best Practices

  • Tie AC-21(1) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims automated decision support but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Automated Decision Support (AC-21(1))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to automated decision support; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Automated Decision Support on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-21(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.514 Minimum Necessary — decision support helps limit disclosures.
  • 164.308(a)(4) Information Access Management — guide appropriate sharing.
  • 164.530 Privacy Rule administrative requirements — consistent disclosure decisions.
  • 164.312(a)(1) Access Control — technical aids for authorization decisions.

Compliance Tips

  • List AC-21(1) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Replace privacy staff?

No — automate guidance; escalate edge cases to privacy/HIM.

Where embed?

ROI systems, EHR share dialogs, and research request portals.

Log decisions?

Yes — retain what the tool recommended and what the user did.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-21(1)
  • Related controls: AC-21, AC-3, AU-2

Need Help Implementing AC-21(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.