AC-4(11) Access Control

Configuration of Security or Privacy Policy Filters

High Risk Moderate Medium Cost

AC-4(11) requires configuration of security or privacy policy filters as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Govern filter rule configuration (field redaction, destination lists, consent checks) under change control with dual review for production ePHI paths. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Configure security and privacy policy filters according to organization-defined policy relevant to ePHI flows.

Implementation Guidance

  1. Treat filter configuration as production config under CM.
  2. Require privacy review for rule changes affecting ePHI fields.
  3. Use dual review before promoting to production.
  4. Test in nonprod with realistic CCD/FHIR samples.
  5. Document rollback for bad filter deploys.
  6. Inventory all filter engines and owners.
  7. Revalidate after HIE/EHR upgrades.
  8. Prohibit direct prod edits outside pipeline.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Redaction rule change control

Changing which FHIR fields are redacted for community share requires CAB plus privacy sign-off.

Destination list edit

Adding a new BA SFTP target to the allow filter needs security review and BAA verification.

Consent-check config

Toggling consent evaluation mode on the HIE broker is version-controlled with rollback tested.

Best Practices

  • Tie AC-4(11) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims configuration of security or privacy policy filters but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Configuration of Security or Privacy Policy Filters (AC-4(11))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to configuration of security or privacy policy filters; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Configuration of Security or Privacy Policy Filters on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(11).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(11) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Are filter rules code?

Treat them as production config under CM — version, review, promote.

Can one engineer edit prod filters?

Prefer dual review for production ePHI filter changes.

How often revalidate?

After major EHR/HIE upgrades and at least annually.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(11)
  • Related controls: AC-4, AC-4(8), AC-4(10), CM-2

Need Help Implementing AC-4(11)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.