Part 2 substance-use chart
A care coordinator outside the Part 2 program cannot open the encounter even if a colleague tries to share a link — label policy denies unless consent/authorization attributes are present.
AC-3(3) requires enforcing mandatory access control (MAC) over organization-defined subjects and objects, using organization-defined attributes (e.g., labels, classifications) that users cannot unilaterally change. In healthcare, MAC-style patterns appear when VIP/psych/substance-use records carry sensitivity labels that block casual sharing, when research datasets are compartmented, or when OS SELinux/AppArmor policies stop EHR service accounts from reading arbitrary host files — regardless of what a local admin wants to share.
Enforce non-discretionary access rules based on sensitivity labels or equivalent attributes so ePHI protections cannot be weakened by ad-hoc user sharing decisions.
How this control shows up in healthcare and HIPAA-covered environments.
A care coordinator outside the Part 2 program cannot open the encounter even if a colleague tries to share a link — label policy denies unless consent/authorization attributes are present.
Dataset labeled 'Identifiable Research — Protocol 22' is readable only by cleared analysts; copying to a general SharePoint library is blocked by DLP/MAC rules.
SELinux confines the interface engine so a compromised process cannot read /etc/shadow or unrelated PHI directories on the host.
Assessors examine whether special-category ePHI has technical non-discretionary enforcement. Policy-only VIP protection without labels/enforcement is a frequent gap.
How this NIST control supports HIPAA Security Rule expectations.
No. RBAC (AC-3(7)) assigns permissions by role; MAC enforces label/clearance rules users cannot override at will.
Host MAC is one implementation path. Application/data labeling that users cannot unilaterally weaken can also meet the enhancement intent for ePHI objects.
Part 2-style restrictions are a strong healthcare example of non-discretionary rules over substance-use information.
Related controls that commonly accompany AC-3(3).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.