AC-4(12) Access Control

Data Type Identifiers

High Risk Complex Medium Cost

AC-4(12) requires data type identifiers as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Identify data types in motion (CCD, FHIR, claims 837, DICOM, CSV extracts) so filters and routes apply type-specific ePHI rules. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Identify data types when transferring information so flow controls can apply type-appropriate ePHI protections.

Implementation Guidance

  1. Catalog data types in motion (CCD, FHIR, 837, DICOM, CSV).
  2. Deploy robust type identification beyond file extensions.
  3. Map each type to a flow policy profile.
  4. Quarantine unknown types that may hold ePHI.
  5. Keep signatures/parsers updated.
  6. Separate claims vs clinical vs research type rules.
  7. Log type ID decisions with transfers.
  8. Test adversarial renaming of PHI files.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

CCD vs plain PDF

Gateway identifies CCD XML and applies clinical document rules; generic PDF with scanned charts gets different DLP profile.

837 claims type

EDI type identifier routes claims through billing controls, not research extract rules.

DICOM vs JPEG

Imaging export identified as DICOM invokes private-tag scrub; plain JPEG photo of a whiteboard uses screenshot DLP rules.

Best Practices

  • Tie AC-4(12) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims data type identifiers but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Data Type Identifiers (AC-4(12))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to data type identifiers; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Data Type Identifiers on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(12).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(12) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

What if type is unknown?

Fail closed or quarantine unknown types that may contain ePHI.

Is MIME type enough?

Use robust identifiers; attackers rename extensions.

Do claims and clinical share rules?

No — apply type-specific policies.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(12)
  • Related controls: AC-4, AC-4(5), SI-12

Need Help Implementing AC-4(12)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.