AC-3(4) Access Control

AC-3(4) Discretionary Access Control

High Risk Moderate Low Cost

AC-3(4) requires enforcing discretionary access control (DAC) over organization-defined subjects and objects, allowing owners/stewards to grant or deny access within organizational policy. Healthcare relies on DAC daily: team chart sharing, Care Team lists, department SharePoint libraries, and imaging teaching files. Without guardrails, discretionary sharing becomes 'Domain Users – Modify' on folders full of discharge summaries.

Control Objective

Allow authorized owners to manage access to their ePHI objects within policy bounds, while preventing uncontrolled discretionary grants that broaden ePHI exposure.

Implementation Guidance

  1. Identify systems where users can share: EHR Care Team, OneDrive/SharePoint, file servers, PACS teaching folders, secure messaging.
  2. Define what owners may grant (view vs edit vs reshare) and maximum audience (named users/groups, not 'Everyone').
  3. Disable anonymous links and external reshare for repositories that may hold ePHI.
  4. Prefer security groups managed by IAM over per-user ACL sprawl.
  5. Run periodic effective-permission reviews on high-risk shares.
  6. Educate owners that discretionary share ≠ HIPAA authorization for disclosure outside TPO without review.
  7. Combine DAC with DLP and sensitivity labels so shares cannot escape classification rules (AC-3(3)).
  8. Log sharing events and alert on unusually broad grants.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Care team adds covering hospitalist

Attending uses EHR discretionary Care Team add for a covering MD — allowed. Attempt to add 'All Hospital Staff' group is blocked by policy/config.

Clinic manager shares quality folder

Manager grants the QI analysts group read access to a de-identified metrics library; attempt to use a guest link for an outside consultant is denied pending BAA and privacy review.

Radiology teaching file

Radiologist shares interesting cases with residents via a restricted group. DAC permits resident view; export-to-USB remains blocked by endpoint controls.

Best Practices

  • Cap discretionary share scope (no org-wide by default).
  • Ban anonymous ePHI links.
  • Prefer groups over individual ACLs.
  • Review broad shares quarterly.
  • Train owners on minimum necessary sharing.
  • Alert on external guest grants involving PHI libraries.

Common Gaps & Violations

  • Everyone/Full Control on departmental PHI folders.
  • External sharing enabled tenant-wide.
  • Orphaned shares after staff leave.
  • Owners granting edit when view would suffice.
  • No review of discretionary ACLs ever.

Required Documentation

  • DAC / sharing policy for ePHI repositories
  • Configuration baselines (SharePoint/EHR sharing settings)
  • Owner responsibilities guide
  • Periodic share review reports
  • Exception process for external collaborators

How to Test & Validate

  1. Attempt org-wide or anonymous share on an ePHI library; confirm deny.
  2. Verify an owner can grant access to an approved group within policy.
  3. Sample shares for departed users still listed.
  4. Confirm external guest sharing requires extra approval where ePHI possible.
  5. Review alerts for broad discretionary grants.

Audit Considerations

Assessors sample file shares and collaboration sites for open ACLs. Discretionary freedom without ceilings is a common HIPAA technical-safeguard weakness.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — authorized persons only; discretionary grants must stay inside that rule.
  • 164.514(d) Minimum Necessary — discretionary sharing should reflect need-to-know.
  • 164.308(a)(4) Information Access Management — policies for access establishment and modification cover owner-driven grants.
  • 164.530(c) Safeguards — reasonable administrative/technical safeguards for PHI in collaborative stores.

Compliance Tips

  • Default new team sites to private with named owners.
  • Put 'no ePHI on open links' in annual security training with a screenshot example.
  • Inventory sites with external sharing enabled before the next assessment.

Frequently Asked Questions

Is DAC incompatible with least privilege?

No. DAC lets owners grant within bounds; least privilege (AC-6) and policy define those bounds.

Who is the 'owner' in an EHR?

Often the chart is not user-owned; Care Team or encounter-based discretionary adds are the EHR analog — still constrain them.

Can we disable all user sharing?

Possible for high-risk repos; balance clinical collaboration needs with controlled DAC settings.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-3(4)
  • Related: AC-3, AC-3(3), AC-6, MP-2, SI-12

Need Help Implementing AC-3(4)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.