AC-4(13) Access Control

Decomposition into Policy-Relevant Subcomponents

High Risk Very Complex High Cost

AC-4(13) requires decomposition into policy-relevant subcomponents as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Decompose complex clinical payloads into policy-relevant parts (demographics vs clinical notes vs billing) so filters can release only allowed subcomponents. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Decompose information into policy-relevant subcomponents to apply precise security and privacy flow decisions on ePHI.

Implementation Guidance

  1. Identify complex packages needing decomposition (Bundles, chart exports).
  2. Define policy-relevant subcomponents (demographics, notes, billing).
  3. Implement filters that can release subsets only.
  4. Align with minimum necessary for each disclosure type.
  5. Prevent reassembly loopholes that recombine held parts.
  6. Log which subcomponents were released.
  7. Pilot on FHIR Bundles before legacy blobs.
  8. Train ROI staff on component-level releases.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Release demographics only

Complex chart package is decomposed; filter releases demographics and meds list, holds psychotherapy narrative.

Billing without clinical notes

Decomposition allows claims subcomponent outward while clinical note subcomponent stays in EHR domain.

Research limited dataset

Pipeline splits identifiers from clinical facts; only approved limited-dataset subcomponents reach the researcher drop.

Best Practices

  • Tie AC-4(13) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims decomposition into policy-relevant subcomponents but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Decomposition into Policy-Relevant Subcomponents (AC-4(13))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to decomposition into policy-relevant subcomponents; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Decomposition into Policy-Relevant Subcomponents on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(13).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(13) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Is this field-level encryption?

Not necessarily — it is decomposing payloads so policy can allow some parts and hold others.

Hard on legacy HL7?

Start with document packages and FHIR Bundles where decomposition is easier.

Relation to minimum necessary?

Directly supports releasing only needed subcomponents.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(13)
  • Related controls: AC-4, AC-4(8), AC-4(12)

Need Help Implementing AC-4(13)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.