Marketing patient story
Monthly review catches a blog photo showing a visible wristband MRN — content removed same day.
AC-22(1) enhances AC-22 by focusing on review of publicly accessible content. Review publicly accessible content (websites, patient stories, directories, open datasets) for accidental ePHI or sensitive operational detail. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Review publicly accessible organizational content on a defined cadence to detect and remove inappropriate ePHI or sensitive information.
How this control shows up in healthcare and HIPAA-covered environments.
Monthly review catches a blog photo showing a visible wristband MRN — content removed same day.
Analyst finds a 'de-identified' file with quasi-identifiers; dataset pulled pending expert determination.
Review removes an accidentally uploaded call schedule with personal cells and clinic vault codes.
Assessors look for operating evidence of Review of Publicly Accessible Content on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-22(1).
How this NIST control supports HIPAA Security Rule expectations.
Define cadence (e.g., monthly) plus event-driven reviews after campaigns.
Websites, social, directories, open data, public PDFs, and similar.
Remove/restrict, risk assess, and follow incident procedures if needed.
Related controls that commonly accompany AC-22(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.