API gateway denies unauthorized partner
A third-party app requests patient read without proper scopes; AC-24 decision at the gateway denies and logs.
AC-24 establishes and applies access control decisions that enforce organization-defined access control policies. Healthcare needs reliable decision points—API gateways, EHR security services, and IdP policy engines—that consistently allow or deny ePHI operations.
Ensure access control decisions for ePHI systems are defined, enforced at decision/enforcement points, and aligned to policy.
How this control shows up in healthcare and HIPAA-covered environments.
A third-party app requests patient read without proper scopes; AC-24 decision at the gateway denies and logs.
Only credentialed providers with active privileges receive permit decisions for CPOE; students receive supervised limited decisions.
Emergency access triggers a distinct decision path with heightened auditing rather than permanent wide-open roles.
Auditors distinguish role assignment from whether decisions are actually enforced at runtime.
How this NIST control supports HIPAA Security Rule expectations.
AC-3 requires enforcement of access policy; AC-24 emphasizes establishing and applying the decisions that carry out that enforcement.
Yes if decisions are consistently applied at enforcement points for each ePHI operation.
AC-25 strengthens integrity guarantees for decision and enforcement mechanisms.
Related controls that commonly accompany AC-24.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.