DLP disable for EHR cutover
Interface lead needs filters off for two hours; change ticket enables disable with dual approval and auto-reenable.
AC-4(10) requires enable and disable security or privacy policy filters as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Strictly control who can turn filters on/off; disabling DLP/HIE filters must be authorized, logged, and time-boxed. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Provide privileged capability to enable or disable security/privacy policy filters only under authorized, auditable conditions.
How this control shows up in healthcare and HIPAA-covered environments.
Interface lead needs filters off for two hours; change ticket enables disable with dual approval and auto-reenable.
Helpdesk account cannot toggle HIE privacy filters — only security-engineering role with logging.
Weekly report shows a filter left disabled after a weekend project; auto-alert forces remediation.
Assessors look for operating evidence of Enable and Disable Security or Privacy Policy Filters on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(10).
How this NIST control supports HIPAA Security Rule expectations.
Only named privileged roles under change control — never standing helpdesk rights.
Yes — time-box disables and alert when still off.
Yes — treat filter disable as a security-relevant event.
Related controls that commonly accompany AC-4(10).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.