AC-23 Access Control

Data Mining Protection

High Risk Moderate Medium Cost

AC-23 protects organizational information from data mining by detecting and preventing (or responding to) data mining attempts. Healthcare warehouses, EHR reporting databases, and population-health marts are prime targets for excessive bulk extraction of patient cohorts.

Control Objective

Detect and prevent unauthorized data-mining style access against systems that store or present ePHI at scale.

Implementation Guidance

  1. Identify high-volume query surfaces: EHR reporting, EDW, FHIR bulk export, CDI tools.
  2. Apply row limits, rate limits, and just-in-time access for analytic roles.
  3. Alert on anomalous bulk selects, mass chart opens, or unusual export jobs.
  4. Require tickets/purpose codes for large extracts; DLP on outbound files.
  5. Segregate production EHR OLTP from analytics replicas with stricter controls.
  6. Review research and quality-abstractor accounts monthly.
  7. Contractually bind BAs that run mining-like workloads.
  8. Tabletop an insider bulk-theft scenario.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EDW analyst pulls full oncology cohort

Rate limits and purpose-coded access stop an unapproved full-table dump; SOC investigates under AC-23 monitoring.

EHR mass chart opens

A user opens hundreds of unrelated charts in minutes; mining-style detection flags and disables the session pending review.

Bulk FHIR export governance

Population health bulk export requires an approved project ID and is capped; unauthorized clients cannot mine the patient directory.

Best Practices

  • Monitor bulk access patterns.
  • Separate analytics from OLTP.
  • Purpose-code large extracts.
  • DLP on exports.
  • Review analytic entitlements.
  • Include BA analytics in scope.

Common Gaps & Violations

  • Unlimited SQL for all analysts.
  • No alerts on mass chart access.
  • Research copies without monitoring.
  • Ignoring FHIR bulk endpoints.
  • Focusing only on external attackers.

Required Documentation

  • Data mining protection standard (AC-23)
  • Monitored systems list
  • Alert thresholds and response runbooks
  • Extract approval workflow
  • Sample investigation tickets

How to Test & Validate

  1. Simulate bulk query over threshold; confirm alert.
  2. Verify export approval gates.
  3. Review analytic role memberships.
  4. Test FHIR bulk authorization.
  5. Sample DLP hits on large PHI files.

Audit Considerations

AC-23 evidence is detection and prevention of bulk harvesting—not only encryption at rest.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis — bulk ePHI theft is a high-impact threat.
  • 164.312(b) Audit Controls — examine activity indicative of mining.
  • 164.514 Minimum Necessary — mining often violates minimum necessary.
  • 164.308(a)(4) Access Management — limit analytic access.

Compliance Tips

  • Put mass-access use cases in the SIEM pack.
  • Treat quality and research users as high-risk entitlements.
  • Cap self-service BI against identifiable ePHI.

Frequently Asked Questions

Is AC-23 only about malicious outsiders?

No—insider and misconfigured analytics are common healthcare mining paths.

Does tokenization remove the need for AC-23?

It reduces risk, but identifiable marts and EHR reporting still need mining protections.

How related to AU-6?

AU-6 reviews audit records; AC-23 specifically targets data-mining behavior patterns.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-23
  • Related controls: AC-3, AC-6, AU-6, SI-4, MP-5

Need Help Implementing AC-23?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.