Patient portal directory listing fixed
Legacy /assets folder listed backup SQL files. AC-3(6) remediation disables indexing and moves backups off the web root — preventing bulk ePHI theft via 'system information' exposure.
AC-3(6) requires protecting organization-defined user and system information while being processed, stored, or transmitted within the system — beyond the primary ePHI objects themselves. Examples include usernames in logs, process listings that reveal clinical app architecture, directory indexes on web servers, diagnostic dumps, and system documentation. Attackers and curious insiders use this metadata to find ePHI paths or impersonate users.
Prevent unauthorized access to user and system metadata that could expose ePHI, weaken privacy, or enable further compromise of healthcare systems.
How this control shows up in healthcare and HIPAA-covered environments.
Legacy /assets folder listed backup SQL files. AC-3(6) remediation disables indexing and moves backups off the web root — preventing bulk ePHI theft via 'system information' exposure.
Only Tier-2 identity staff can search the full enterprise directory for VIP accounts; front-line scripts return minimal attributes.
Support session policy blocks unattended control and forbids exporting system configuration files without ticketed approval and redaction review.
Technical tests often find forgotten directory listings or verbose errors. These are treated as access-control failures even when the 'main' EHR login works correctly.
How this NIST control supports HIPAA Security Rule expectations.
No — it covers user and system information that can enable ePHI compromise or privacy harm.
Not always, but user directories tied to care relationships or VIP status can be sensitive; restrict broadly.
AC-3(5) focuses on security-control data; AC-3(6) covers broader user/system information protection during processing, storage, and transmission.
Related controls that commonly accompany AC-3(6).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.