CCD vs plain PDF
Gateway identifies CCD XML and applies clinical document rules; generic PDF with scanned charts gets different DLP profile.
AC-4(12) requires data type identifiers as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Identify data types in motion (CCD, FHIR, claims 837, DICOM, CSV extracts) so filters and routes apply type-specific ePHI rules. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Identify data types when transferring information so flow controls can apply type-appropriate ePHI protections.
How this control shows up in healthcare and HIPAA-covered environments.
Gateway identifies CCD XML and applies clinical document rules; generic PDF with scanned charts gets different DLP profile.
EDI type identifier routes claims through billing controls, not research extract rules.
Imaging export identified as DICOM invokes private-tag scrub; plain JPEG photo of a whiteboard uses screenshot DLP rules.
Assessors look for operating evidence of Data Type Identifiers on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(12).
How this NIST control supports HIPAA Security Rule expectations.
Fail closed or quarantine unknown types that may contain ePHI.
Use robust identifiers; attackers rename extensions.
No — apply type-specific policies.
Related controls that commonly accompany AC-4(12).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.