Redaction rule change control
Changing which FHIR fields are redacted for community share requires CAB plus privacy sign-off.
AC-4(11) requires configuration of security or privacy policy filters as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Govern filter rule configuration (field redaction, destination lists, consent checks) under change control with dual review for production ePHI paths. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Configure security and privacy policy filters according to organization-defined policy relevant to ePHI flows.
How this control shows up in healthcare and HIPAA-covered environments.
Changing which FHIR fields are redacted for community share requires CAB plus privacy sign-off.
Adding a new BA SFTP target to the allow filter needs security review and BAA verification.
Toggling consent evaluation mode on the HIE broker is version-controlled with rollback tested.
Assessors look for operating evidence of Configuration of Security or Privacy Policy Filters on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(11).
How this NIST control supports HIPAA Security Rule expectations.
Treat them as production config under CM — version, review, promote.
Prefer dual review for production ePHI filter changes.
After major EHR/HIE upgrades and at least annually.
Related controls that commonly accompany AC-4(11).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.