Part 2 note blocked from general HIE
Encounter tagged Part2 cannot route to the community HIE without consent attributes — enforcement reads object privacy attributes.
AC-4(1) requires object security and privacy attributes as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Bind flow decisions to object security/privacy attributes (sensitivity, consent, Part 2, research tags) so unlabeled ePHI cannot freely egress. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Enforce information flow using security and privacy attributes associated with ePHI objects, sources, and destinations.
How this control shows up in healthcare and HIPAA-covered environments.
Encounter tagged Part2 cannot route to the community HIE without consent attributes — enforcement reads object privacy attributes.
Warehouse job stamps protocol and identifiable flags; only cleared destinations accept the object.
VIP-sensitivity attribute blocks release to lobby printers; HIM secure printers remain allowed.
Assessors look for operating evidence of Object Security and Privacy Attributes on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(1).
How this NIST control supports HIPAA Security Rule expectations.
ACLs authorize subjects; this enhancement uses security/privacy attributes on objects to decide whether information may flow to a destination.
Label at object/message granularity that enforcement points can evaluate; full field-level labeling is advanced maturity.
Route high-sensitivity classes through attribute-aware brokers or block them from that path.
Related controls that commonly accompany AC-4(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.