AC-22(1) Access Control

Review of Publicly Accessible Content

Medium Risk Easy Low Cost

AC-22(1) enhances AC-22 by focusing on review of publicly accessible content. Review publicly accessible content (websites, patient stories, directories, open datasets) for accidental ePHI or sensitive operational detail. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.

Control Objective

Review publicly accessible organizational content on a defined cadence to detect and remove inappropriate ePHI or sensitive information.

Implementation Guidance

  1. Inventory publicly accessible content properties.
  2. Define review cadence (e.g., monthly) and owners.
  3. Scan for ePHI, credentials, and sensitive ops data.
  4. Remove/restrict findings same day when PHI found.
  5. Trigger incident process when required.
  6. Include social, directories, open data, PDFs.
  7. Track findings to closure.
  8. Brief marketing/comms on PHI-in-public risks.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Marketing patient story

Monthly review catches a blog photo showing a visible wristband MRN — content removed same day.

Open data portal

Analyst finds a 'de-identified' file with quasi-identifiers; dataset pulled pending expert determination.

Provider directory PDF

Review removes an accidentally uploaded call schedule with personal cells and clinic vault codes.

Best Practices

  • Tie AC-22(1) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims review of publicly accessible content but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Review of Publicly Accessible Content (AC-22(1))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to review of publicly accessible content; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Review of Publicly Accessible Content on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-22(1).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.530(c) Safeguards — protect PHI from intentional/unintentional disclosure including via public content.
  • 164.502 Uses and Disclosures — public posting of PHI is generally impermissible without authorization.
  • 164.308(a)(1) Risk Analysis — public web content as a disclosure vector.
  • 164.308(a)(6) Security Incident Procedures — respond when ePHI is found publicly posted.

Compliance Tips

  • List AC-22(1) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

How often review?

Define cadence (e.g., monthly) plus event-driven reviews after campaigns.

What is in scope?

Websites, social, directories, open data, public PDFs, and similar.

Find PHI — then what?

Remove/restrict, risk assess, and follow incident procedures if needed.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-22(1)
  • Related controls: AC-22, SI-4, AU-6

Need Help Implementing AC-22(1)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.