EDW analyst pulls full oncology cohort
Rate limits and purpose-coded access stop an unapproved full-table dump; SOC investigates under AC-23 monitoring.
AC-23 protects organizational information from data mining by detecting and preventing (or responding to) data mining attempts. Healthcare warehouses, EHR reporting databases, and population-health marts are prime targets for excessive bulk extraction of patient cohorts.
Detect and prevent unauthorized data-mining style access against systems that store or present ePHI at scale.
How this control shows up in healthcare and HIPAA-covered environments.
Rate limits and purpose-coded access stop an unapproved full-table dump; SOC investigates under AC-23 monitoring.
A user opens hundreds of unrelated charts in minutes; mining-style detection flags and disables the session pending review.
Population health bulk export requires an approved project ID and is capped; unauthorized clients cannot mine the patient directory.
AC-23 evidence is detection and prevention of bulk harvesting—not only encryption at rest.
How this NIST control supports HIPAA Security Rule expectations.
No—insider and misconfigured analytics are common healthcare mining paths.
It reduces risk, but identifiable marts and EHR reporting still need mining protections.
AU-6 reviews audit records; AC-23 specifically targets data-mining behavior patterns.
Related controls that commonly accompany AC-23.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.