Block raw SQL to EHR database
Analysts lose direct production SQL that bypassed app authorization; reporting moves to mediated views.
AC-25 implements a reference monitor that mediates access attempts, is tamper-resistant, and is small enough to analyze and test. Commercial EHRs rarely expose a classical security kernel, but healthcare organizations still apply the intent: non-bypassable authorization on APIs and databases, protected policy stores, and testable enforcement modules for ePHI.
Ensure critical ePHI access mediation is non-bypassable, protected from tampering, and verifiable through analysis and testing.
How this control shows up in healthcare and HIPAA-covered environments.
Analysts lose direct production SQL that bypassed app authorization; reporting moves to mediated views.
Microservice PRs fail CI if ePHI routes do not invoke the shared authorization library.
A change to security policy outside CAB triggers an alert; enforcement config is integrity-monitored.
AC-25 is advanced; assessors accept risk-based application of the intent on commercial EHRs if bypasses are controlled and documented.
How this NIST control supports HIPAA Security Rule expectations.
Not typically for COTS EHR; apply non-bypassable, tamper-resistant, testable mediation as far as architecture allows.
Confirm your overlay; implement intent where ePHI bypass risk is high.
AC-3 requires enforcement; AC-25 strengthens integrity and non-bypassability of the enforcement mechanism.
Related controls that commonly accompany AC-25.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.