AC-22 Access Control

Publicly Accessible Content

Medium Risk Easy Low Cost

AC-22 requires designating individuals authorized to post information onto publicly accessible organizational systems, training them to ensure nonpublic information is not posted, reviewing content before publication for nonpublic information, and removing nonpublic information if it is posted. For healthcare organizations this protects websites, patient-facing portals, social posts, job boards, and status pages from accidentally publishing ePHI, staff credentials, or internal diagrams.

Control Objective

Make sure anything published to the public internet is reviewed and owned — so ePHI and other nonpublic information never appears on public pages by mistake.

Implementation Guidance

  1. Inventory public surfaces: marketing site, career pages, patient education blogs, portal landing pages, provider directories, social media, community forums, and public status/statusfile buckets.
  2. Name authorized publishers per channel; remove anonymous CMS admin sprawl.
  3. Train publishers on what must never be posted (ePHI, full names with clinical details, screenshots of EHR, internal IPs, VPN instructions with secrets).
  4. Require pre-publication review for higher-risk content (case stories, photos, press releases, research summaries).
  5. Scan public sites periodically for MRNs, emails, phone lists, open directories, and exposed .pdf/.xlsx uploads.
  6. Define an emergency takedown procedure with hosting/CMS access and on-call contacts.
  7. Separate public CMS from clinical networks; never reuse EHR screenshots in marketing without de-identification review.
  8. Review third-party widgets and forms so they do not collect unnecessary PHI on public pages without safeguards.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Success story that named a patient condition

Marketing drafts a web story with a recognizable patient photo and diagnosis. AC-22 review by privacy stops publication until authorization and de-identification standards are met — avoiding a public PHI disclosure.

Job posting with internal org chart

HR uploads a PDF that includes staff email lists and a network diagram used in an all-hands deck. Content review catches it; the public careers page gets a scrubbed version.

Misconfigured public storage bucket

A contractor hosts brochure PDFs in a cloud bucket that also contains a spreadsheet of event registrants with DOBs. AC-22 monitoring/crawl finds the listing; the bucket policy is corrected and the file removed within the takedown SLA.

Best Practices

  • Least privilege on CMS and social publishing accounts.
  • Dual review for patient stories, images, and research content.
  • Automated crawls for sensitive patterns on public domains.
  • Fast takedown runbook tested annually.
  • Ban EHR screenshots from public decks unless privacy-approved.
  • Include partners/agencies who post on your behalf in the same rules.

Common Gaps & Violations

  • Many staff have WordPress/admin rights with no content training.
  • Patient testimonials published with identifiers and no authorization.
  • Old PDFs left publicly downloadable after events.
  • Open cloud storage or directory listings on the public site.
  • No process to remove content quickly after a privacy complaint.

Required Documentation

  • Public content publishing policy (AC-22)
  • Authorized publisher list by channel
  • Pre-publication review checklist
  • Takedown / incident procedure for exposed content
  • Evidence of periodic public-site reviews or scans

How to Test & Validate

  1. Confirm only authorized accounts can publish to the main public CMS.
  2. Submit a test draft containing synthetic PHI markers and verify review catches it.
  3. Crawl public URLs for sensitive file types and unexpected listings.
  4. Execute a tabletop takedown: time-to-remove a test page.
  5. Sample social posts from the last quarter for policy adherence.

Audit Considerations

Auditors may simply Google your domain and open PDFs. Be ready to show who can publish, how review works, and how fast you can remove mistaken posts. Public PHI exposure is both a privacy and security finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.502 Uses and Disclosures of PHI — publishing PHI publicly generally requires authorization or another valid permission.
  • 164.514 De-identification — content intended for public use must meet de-identification or limited data set rules when derived from PHI.
  • 164.530(c) Safeguards — reasonable safeguards to limit incidental uses/disclosures apply to publishing workflows.
  • 164.312(a)(1) Access Control — administrative access to public CMS should be limited to authorized publishers.

Compliance Tips

  • Add privacy sign-off to the marketing content calendar for patient-related posts.
  • Keep a scrubbed media library; quarantine anything sourced from clinical systems.
  • After website redesigns, re-run a public content sweep for leftover files.

Frequently Asked Questions

Does AC-22 apply only to the main website?

No. It covers any publicly accessible organizational system — portals, cloud buckets used publicly, social channels, and similar surfaces.

Can we post patient success stories?

Only with proper authorization and privacy review, or after valid de-identification. AC-22 requires that check before posting.

How does AC-22 relate to AC-14?

AC-14 addresses actions allowed without authentication. AC-22 focuses on controlling what content is published on public systems and removing nonpublic information if posted.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-22 Publicly Accessible Content
  • HIPAA Privacy Rule §§ 164.502, 164.514, 164.530(c)
  • Related controls: AC-14, AC-21, AU-2, SI-12, AT-2

Need Help Implementing AC-22?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.