Control Objective
Make sure anything published to the public internet is reviewed and owned — so ePHI and other nonpublic information never appears on public pages by mistake.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Success story that named a patient condition
Marketing drafts a web story with a recognizable patient photo and diagnosis. AC-22 review by privacy stops publication until authorization and de-identification standards are met — avoiding a public PHI disclosure.
Job posting with internal org chart
HR uploads a PDF that includes staff email lists and a network diagram used in an all-hands deck. Content review catches it; the public careers page gets a scrubbed version.
Misconfigured public storage bucket
A contractor hosts brochure PDFs in a cloud bucket that also contains a spreadsheet of event registrants with DOBs. AC-22 monitoring/crawl finds the listing; the bucket policy is corrected and the file removed within the takedown SLA.
Audit Considerations
Auditors may simply Google your domain and open PDFs. Be ready to show who can publish, how review works, and how fast you can remove mistaken posts. Public PHI exposure is both a privacy and security finding.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.502 Uses and Disclosures of PHI — publishing PHI publicly generally requires authorization or another valid permission.
- 164.514 De-identification — content intended for public use must meet de-identification or limited data set rules when derived from PHI.
- 164.530(c) Safeguards — reasonable safeguards to limit incidental uses/disclosures apply to publishing workflows.
- 164.312(a)(1) Access Control — administrative access to public CMS should be limited to authorized publishers.