AC-4(10) Access Control

Enable and Disable Security or Privacy Policy Filters

High Risk Moderate Medium Cost

AC-4(10) requires enable and disable security or privacy policy filters as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Strictly control who can turn filters on/off; disabling DLP/HIE filters must be authorized, logged, and time-boxed. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Provide privileged capability to enable or disable security/privacy policy filters only under authorized, auditable conditions.

Implementation Guidance

  1. Limit enable/disable rights to named privileged roles.
  2. Require change ticket and dual approval for production disables.
  3. Auto-expire temporary disables.
  4. Log all filter toggle events to SIEM.
  5. Alert when filters remain disabled past window.
  6. Prohibit helpdesk standing toggle rights.
  7. Test re-enable automation.
  8. Review toggle events monthly.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

DLP disable for EHR cutover

Interface lead needs filters off for two hours; change ticket enables disable with dual approval and auto-reenable.

Unauthorized filter bypass

Helpdesk account cannot toggle HIE privacy filters — only security-engineering role with logging.

Forgotten disable found

Weekly report shows a filter left disabled after a weekend project; auto-alert forces remediation.

Best Practices

  • Tie AC-4(10) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims enable and disable security or privacy policy filters but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Enable and Disable Security or Privacy Policy Filters (AC-4(10))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to enable and disable security or privacy policy filters; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Enable and Disable Security or Privacy Policy Filters on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(10).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(10) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Who may disable filters?

Only named privileged roles under change control — never standing helpdesk rights.

Should disables auto-expire?

Yes — time-box disables and alert when still off.

Must disables be logged?

Yes — treat filter disable as a security-relevant event.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(10)
  • Related controls: AC-4, AC-4(8), AC-4(11), AU-2

Need Help Implementing AC-4(10)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.