AC-4 Access Control

Information Flow Enforcement

High Risk Complex Medium Cost

AC-4 requires the information system to enforce approved authorizations for controlling the flow of information within the system and between interconnected systems based on organization-defined information flow control policies. In healthcare this is how you keep ePHI from moving freely across VLANs, cloud apps, HL7/FHIR interfaces, email, and USB — beyond who can log in (AC-3) to where data is allowed to go.

Control Objective

Ensure ePHI and other sensitive data can only travel along approved paths — between approved systems, users, and networks — and are blocked everywhere else.

Implementation Guidance

  1. Map real data flows: EHR ↔ lab, imaging, billing, HIE, patient portal, backup, analytics, and BA clouds. Diagram sources, destinations, protocols, and data classes.
  2. Write flow policies: which systems may exchange ePHI, in which direction, over which protocols, and with what inspection/encryption.
  3. Enforce with layered controls: network ACLs/firewalls, reverse proxies, API gateways, email DLP, CASB, and application-level interface accounts scoped to required transactions.
  4. Segment clinical, biomed, guest, and corporate networks so a compromised guest device cannot pull charts from the EHR VLAN.
  5. Restrict east-west traffic inside the data center; do not rely only on perimeter firewalls.
  6. Monitor denied flows and unexpected new destinations (new SaaS, new IP for an interface partner).
  7. Re-validate flows after EHR upgrades, mergers, and new telehealth or HIE connections.
  8. Document exceptions (temporary interfaces, cutovers) with owners and end dates.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Lab interface talking to the wrong network

An analyzer was dual-homed and could reach both the lab VLAN and open internet. AC-4 remediation removes the internet path and allows only the approved LIS IP over the required port — containing malware risk and unintended ePHI egress.

Staff emailing spreadsheets of patients

Care managers export census lists to Excel and email them externally. Mail DLP + policy under AC-4 blocks or encrypts messages with MRNs/SSNs to non-approved domains and offers a secure share alternative.

Analytics VPC peering gone wide

A cloud analytics project peered to production and could query more schemas than needed. AC-4 tightens security groups and database grants so only approved views flow to the analytics project — least privilege for data in motion.

Best Practices

  • Maintain a living data-flow inventory tied to your risk analysis.
  • Prefer allow-lists for interface partners over broad any-any rules.
  • Encrypt and authenticate flows that leave your boundary (SC-8/SC-13).
  • Inspect or broker high-risk channels (email, web upload, USB).
  • Alert on new outbound destinations from EHR and interface engines.
  • Pair AC-4 with AC-3 (who) and SC-7 (boundary) as one architecture story.

Common Gaps & Violations

  • Flat clinic network: workstations, EHR, and guest Wi-Fi share one subnet.
  • Interface engines with unrestricted outbound internet.
  • No DLP on email or personal cloud uploads containing ePHI.
  • Firewall rules never reviewed after projects end (temporary becomes permanent).
  • Data-flow diagrams that only exist in a binder and do not match production.

Required Documentation

  • Information flow / data-flow policy
  • Current data-flow diagrams for ePHI systems
  • Firewall/ACL/API allow-lists for major interfaces
  • DLP / CASB rule sets covering ePHI patterns
  • Exception register for temporary flows

How to Test & Validate

  1. From a guest or corporate test host, attempt connections to EHR/PACS; confirm deny where policy requires.
  2. Verify an approved interface still succeeds (lab→LIS).
  3. Send a test email with synthetic MRN patterns to an external address; confirm DLP action.
  4. Review firewall change tickets vs documented flows for drift.
  5. Trace one cloud SaaS integration end-to-end against the allow-list.

Audit Considerations

Auditors want to see that flow control is technical, not aspirational. Bring diagrams that match configs, plus samples of blocked attempts. HIPAA assessors often probe segmentation between guest, biomed, and clinical systems.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limiting who accesses ePHI is incomplete without controlling where ePHI can flow.
  • 164.312(e) Transmission Security — integrity and encryption for ePHI in transit support approved flows.
  • 164.308(a)(1) Risk Analysis — data-flow mapping is foundational to identifying where ePHI moves.
  • 164.308(a)(4) Information Access Management — isolating healthcare clearinghouse functions relates to separating flows by purpose.

Compliance Tips

  • Put data-flow updates on the checklist for every new interface or SaaS go-live.
  • Use synthetic identifiers in DLP testing — never real patient data.
  • Align AC-4 narratives with your HIPAA risk analysis asset/data-flow section.

Frequently Asked Questions

Is AC-4 just a firewall control?

Firewalls are one enforcement point. AC-4 also covers application interfaces, email/web DLP, API gateways, and any broker that allows or denies information movement.

How does AC-4 differ from AC-3?

AC-3 enforces what a user or process may do after authentication. AC-4 enforces whether information is allowed to move along a path between subjects/objects/systems.

Where should a small clinic start?

Segment guest Wi-Fi from clinical systems, lock down EHR/interface outbound internet, and stop uncontrolled email exports of patient lists.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4 Information Flow Enforcement
  • NIST SP 800-41 Guidelines on Firewalls / boundary protection concepts
  • HIPAA Security Rule §§ 164.308(a)(1), 164.308(a)(4), 164.312(a), 164.312(e)
  • Related controls: AC-3, SC-7, SC-8, SI-4, CA-3

Need Help Implementing AC-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.